Critical remote code execution in vm2, a widely used Node.js sandbox library
about.gitlab.com | vulnerability | #rce | #gitlab | #sandbox-escape | #vulnerability | #nodejs | #vm2
Summary
GitLab's Threat Research Group found a critical vm2 sandbox escape (CVSS 10.0) reachable with require.external enabled per the library's README; v3.11.7 blocks it, but config hardening is still urged.
- Published
- Collected
Skip to content