vm2
42 known vulnerabilities · 9 critical · 1 high
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
NodeVM observability builtins leak host process and HTTP request data
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
vm2 has a Sandbox Escape issue
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
vm2 has a Sandbox Escape Vulnerability
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
vm2 has Sandbox Breakout Through Null Proto Exception
vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host
VM2 Has a WASM Sandbox Escape
VM2 Sandbox Breakout Through __lookupGetter__
VM2 Has Sandbox Breakout Through Promise Species
VM2 Has Sandbox Breakout Through Inspect Function
vm2 Has a Sandbox Breakout Using Async Generator
VM2 Has a Sandbox Escape Issue via SuppressedError
vm2 Access to Host Object Enables Sandbox Escape
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak