Security: patriksimek/vm2
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
NodeVM nesting guard accepts array-shaped require and permits host RCEGHSA-8hr7-r645-pc6w published
Aug 24, 2026 by patriksimekCritical -
vm2 leaks absolute host filesystem paths to sandbox code via error stack formattingGHSA-x6m4-chr9-cg97 published
Aug 24, 2026 by patriksimekModerate -
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirectionGHSA-647f-g98j-qq25 published
Aug 24, 2026 by patriksimekCritical -
vm2 3.11.6 allows a sandboxed plugin to execute native code through `node:sqlite`GHSA-6w8r-xxw2-g3hx published
Aug 24, 2026 by patriksimekCritical -
vm2 3.11.6 crypto builtin loads attacker native code through setEngineGHSA-46pr-c5wc-xffx published
Aug 24, 2026 by patriksimekCritical -
vm2 3.11.6 exposes host HTTPS credentials and TLS traffic through globalAgentGHSA-h85j-hv3c-qfgq published
Aug 24, 2026 by patriksimekCritical -
vm2 3.11.6 NodeVM can replace the host process TLS trust storeGHSA-98xx-8mx4-x7cm published
Aug 24, 2026 by patriksimekCritical -
vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)GHSA-r4fx-v8hh-22mv published
Aug 24, 2026 by patriksimekHigh -
Private security report: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protectorGHSA-27g9-p43v-cw3v published
Aug 24, 2026 by patriksimekCritical -
External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlistedGHSA-7q3f-wx44-378m published
Aug 24, 2026 by patriksimekModerate