vm2 is vulnerable to Prototype Pollution
100
Critical Risk
The protected-object inventory used to shield host intrinsics from the sandbox omits the typed-array, ArrayBuffer, and related binary-data prototypes. Sandboxed code walks the prototype chain to reach and mutate host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype. Modifying these host intrinsics corrupts host binary-data handling and undermines the sandbox boundary. The fix registers the binary-data and iterator intrinsics in the protected-object inventory so their host prototypes can no longer be modified.
You are affected if you are using a version that falls within the vulnerable range and you execute untrusted JavaScript in a vm2 sandbox.
vm2 is vulnerable to Prototype Pollution in versions 3.11.0 - 3.11.7.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.