PT-2026-36851 · Npm · Vm2
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.0
Description
vm2 is an open source vm/sandbox for Node.js. The use of
SuppressedError allows attackers to escape the sandbox and execute arbitrary code.Recommendations
Update to version 3.11.0.
Exploit
Fix
Code Injection
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2