Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks
ID: 99372d9c-54b2-5c6f-a9ad-91470f1a7c57
STIX ID: report--99372d9c-54b2-5c6f-a9ad-91470f1a7c57
Feed Name: cybersecurityNews.com
The report discloses eleven critical vulnerabilities in the vm2 Node.js sandboxing library (affecting versions up to 3.11.1), several of which allow full sandbox escape and remote code execution on the host. It enumerates CVEs, affected and patched versions (two CVEs remain unpatched), describes multiple attack techniques (prototype manipulation, Promise species overwrites, WebAssembly exception handling, util.inspect and Module._load abuses), and recommends upgrading to 3.11.1 where available or replacing vm2 with kernel-level isolation (Docker, gVisor, Firecracker) and avoiding unsafe configurations such as nesting:true and wildcard built-ins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
