vm2
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.
Security Advisories for vm2 in npm
High
14 days ago
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
npm
vm2
Critical
14 days ago
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
npm
vm2
Critical
14 days ago
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
npm
vm2
Low
14 days ago
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
npm
vm2
Moderate
about 1 month ago
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
npm
vm2
Critical
about 1 month ago
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
npm
vm2
High
about 1 month ago
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
npm
vm2
Moderate
about 1 month ago
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
npm
vm2
Moderate
about 1 month ago
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
npm
vm2
Moderate
about 1 month ago
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
npm
vm2
High
about 1 month ago
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
npm
vm2
High
about 1 month ago
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
npm
vm2
Critical
about 1 month ago
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
npm
vm2
Critical
about 1 month ago
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
npm
vm2
Critical
over 3 years ago
vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host
npm
vm2