vm2 is vulnerable to Sandbox Escape
98
Critical Risk
vm2 blocks calls to dangerous host prototype mutators to prevent sandbox code from tampering with host object prototypes, but the guard only recognizes direct invocations. Sandbox code bypasses the check by routing the mutator through an indirect call form. This lets sandbox code alter a host error object's prototype and reach the host constructor chain, obtaining a reference to process and executing arbitrary commands on the host. The fix detects and blocks the indirect-call bypass of the prototype mutators.
You are affected if you are using a version that falls within the vulnerable range and you execute untrusted code inside a vm2 sandbox.
vm2 is vulnerable to Sandbox Escape in versions 0.0.1 - 3.11.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant