vm2 is vulnerable to Information Disclosure
58
Medium Risk
vm2 formats error stacks on the host side and forwards .stack reads from the sandbox bridge back to sandboxed code without redaction. Passing malformed source to eval() triggers a host-side SyntaxError whose stack is returned to the sandbox. Sandboxed code reads absolute host filesystem paths, internal Node details, and embedding-application source locations even under default VM and NodeVM configurations. The fix redacts sensitive path information from stack formatting before it reaches the sandbox.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Information Disclosure in versions 3.11.0 - 3.11.6.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant