Vulnerabilities

Last updated 3 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
vm2 vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process High Risk 8.6 9 hours ago 9 hours ago
vm2 vm2: NodeVM custom resolution bypasses external path boundaries Critical 10.0 9 hours ago 9 hours ago
vm2 vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary Critical 10.0 9 hours ago 9 hours ago
vm2 vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix Critical 10.0 10 hours ago 9 hours ago
vm2 vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process High Risk 8.6 10 hours ago 9 hours ago
vm2 vm2: Sandbox Escape (NodeVM) Critical 10.0 10 hours ago 9 hours ago
vm2 vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM High Risk 7.1 10 hours ago 9 hours ago
vm2 vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack Medium Risk 5.8 10 hours ago 10 hours ago
vm2 vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting Medium Risk 5.8 10 hours ago 10 hours ago
vm2 vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit Critical 9.0 10 hours ago 10 hours ago
vm2 vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool Critical 10.0 10 hours ago 10 hours ago
vm2 vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Medium Risk 6.8 4 days ago 4 days ago
vm2 vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts High Risk 8.6 4 days ago 4 days ago
vm2 vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical 9.9 4 days ago 4 days ago
vm2 vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical 9.8 4 days ago 4 days ago
vm2 vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Medium Risk 4.0 4 days ago 4 days ago
vm2 vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection Critical 10.0 4 days ago 4 days ago
vm2 vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes High Risk 8.5 4 days ago 4 days ago
vm2 vm2 allows a sandboxed plugin to execute native code through `node:sqlite` Critical 9.9 4 days ago 4 days ago
vm2 vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical 9.0 4 days ago 4 days ago
vm2 vm2 NodeVM can replace the host process TLS trust store Critical 10.0 4 days ago 4 days ago
vm2 vm2 crypto builtin loads attacker native code through setEngine Critical 9.9 4 days ago 4 days ago
vm2 vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted Medium Risk 4.2 4 days ago 4 days ago
vm2 vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical 9.9 4 days ago 4 days ago
vm2 vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package Critical 9.9 4 days ago 4 days ago
vm2 vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical 10.0 4 days ago 4 days ago
vm2 vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` Medium Risk 5.3 5 months ago 18 days ago
vm2 vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass High Risk 7.5 1 month ago 18 days ago
vm2 vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter Low Risk 3.0 4 months ago 18 days ago
vm2 vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) Critical 10.0 1 month ago 18 days ago
vm2 vm2 Sandbox Escape vulnerability Critical 9.8 3 years ago 26 days ago
vm2 vm2 vulnerable to Inspect Manipulation Medium Risk 5.3 3 years ago 26 days ago
vm2 vm2 vulnerable to sandbox escape Critical 9.8 3 years ago 26 days ago
vm2 vm2 before 3.6.11 vulnerable to sandbox escape High Risk 8.3 4 years ago 26 days ago
vm2 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical 9.8 1 month ago 1 month ago
vm2 vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike High Risk 8.0 1 month ago 1 month ago
vm2 VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE Critical 9.9 1 month ago 1 month ago
vm2 vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE Critical 10.0 4 months ago 3 months ago
vm2 vm2 Sandbox Escape vulnerability Critical 9.8 3 years ago 3 months ago
vm2 Sandbox bypass in vm2 Critical 9.8 4 years ago 3 months ago
vm2 Prototype Pollution in vm2 Critical 9.8 4 years ago 3 months ago
vm2 VM2 Has a WASM Sandbox Escape Critical 9.8 5 months ago 3 months ago
vm2 NodeVM builtin denylist bypass via process and inspector/promises allows host code execution Critical 10.0 4 months ago 3 months ago
vm2 vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass Critical 9.8 4 months ago 3 months ago
vm2 vm2 is Vulnerable to Sandbox Breakout Through Promise Species Critical 10.0 4 months ago 3 months ago
vm2 vm2 has a Sandbox Escape issue Critical 10.0 4 months ago 3 months ago
vm2 NodeVM observability builtins leak host process and HTTP request data Medium Risk 6.0 4 months ago 3 months ago
vm2 vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain High Risk 8.6 4 months ago 3 months ago
vm2 vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks High Risk 8.7 4 months ago 3 months ago
vm2 NodeVM network builtin exclusions bypass via internal _http_client and _http_server High Risk 8.6 4 months ago 3 months ago