Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Critical remote code execution in vm2, a widely used Node.js sandbox library

Summary

GitLab's Threat Research Group found a critical vm2 sandbox escape (CVSS 10.0) reachable with require.external enabled per the library's README; v3.11.7 blocks it, but config hardening is still urged.
Published
Collected

original ↗

Related coverage

back