vm2 is vulnerable to Improper Access Control
85
High Risk
Negative builtin denials are matched by exact module name rather than by module family, so a denial such as -fs blocks only fs and not its subpaths. Sandboxed code requires fs/promises or node:fs/promises to reach filesystem operations despite fs being denied. This allows host file creation and writes that the denylist was meant to prevent. The fix matches denied builtins across their module family.
You are affected if you are using a version that falls within the vulnerable range and you rely on a negative builtin denylist entry such as -fs to block filesystem access.
vm2 is vulnerable to Improper Access Control in versions 0.0.1 - 3.11.6.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant