Vulnerabilities
Last updated 3 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process | High Risk 8.6 | 9 hours ago | 9 hours ago |
|
|
vm2: NodeVM custom resolution bypasses external path boundaries | Critical 10.0 | 9 hours ago | 9 hours ago |
|
|
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary | Critical 10.0 | 9 hours ago | 9 hours ago |
|
|
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix | Critical 10.0 | 10 hours ago | 9 hours ago |
|
|
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process | High Risk 8.6 | 10 hours ago | 9 hours ago |
|
|
vm2: Sandbox Escape (NodeVM) | Critical 10.0 | 10 hours ago | 9 hours ago |
|
|
vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM | High Risk 7.1 | 10 hours ago | 9 hours ago |
|
|
vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack | Medium Risk 5.8 | 10 hours ago | 10 hours ago |
|
|
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting | Medium Risk 5.8 | 10 hours ago | 10 hours ago |
|
|
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit | Critical 9.0 | 10 hours ago | 10 hours ago |
|
|
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool | Critical 10.0 | 10 hours ago | 10 hours ago |
|
|
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks | Medium Risk 6.8 | 4 days ago | 4 days ago |
|
|
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts | High Risk 8.6 | 4 days ago | 4 days ago |
|
|
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape | Critical 9.9 | 4 days ago | 4 days ago |
|
|
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector | Critical 9.8 | 4 days ago | 4 days ago |
|
|
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor | Medium Risk 4.0 | 4 days ago | 4 days ago |
|
|
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection | Critical 10.0 | 4 days ago | 4 days ago |
|
|
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes | High Risk 8.5 | 4 days ago | 4 days ago |
|
|
vm2 allows a sandboxed plugin to execute native code through `node:sqlite` | Critical 9.9 | 4 days ago | 4 days ago |
|
|
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE | Critical 9.0 | 4 days ago | 4 days ago |
|
|
vm2 NodeVM can replace the host process TLS trust store | Critical 10.0 | 4 days ago | 4 days ago |
|
|
vm2 crypto builtin loads attacker native code through setEngine | Critical 9.9 | 4 days ago | 4 days ago |
|
|
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted | Medium Risk 4.2 | 4 days ago | 4 days ago |
|
|
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process | Critical 9.9 | 4 days ago | 4 days ago |
|
|
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package | Critical 9.9 | 4 days ago | 4 days ago |
|
|
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent | Critical 10.0 | 4 days ago | 4 days ago |
|
|
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` | Medium Risk 5.3 | 5 months ago | 18 days ago |
|
|
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass | High Risk 7.5 | 1 month ago | 18 days ago |
|
|
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter | Low Risk 3.0 | 4 months ago | 18 days ago |
|
|
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) | Critical 10.0 | 1 month ago | 18 days ago |
|
|
vm2 Sandbox Escape vulnerability | Critical 9.8 | 3 years ago | 26 days ago |
|
|
vm2 vulnerable to Inspect Manipulation | Medium Risk 5.3 | 3 years ago | 26 days ago |
|
|
vm2 vulnerable to sandbox escape | Critical 9.8 | 3 years ago | 26 days ago |
|
|
vm2 before 3.6.11 vulnerable to sandbox escape | High Risk 8.3 | 4 years ago | 26 days ago |
|
|
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators | Critical 9.8 | 1 month ago | 1 month ago |
|
|
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike | High Risk 8.0 | 1 month ago | 1 month ago |
|
|
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE | Critical 9.9 | 1 month ago | 1 month ago |
|
|
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE | Critical 10.0 | 4 months ago | 3 months ago |
|
|
vm2 Sandbox Escape vulnerability | Critical 9.8 | 3 years ago | 3 months ago |
|
|
Sandbox bypass in vm2 | Critical 9.8 | 4 years ago | 3 months ago |
|
|
Prototype Pollution in vm2 | Critical 9.8 | 4 years ago | 3 months ago |
|
|
VM2 Has a WASM Sandbox Escape | Critical 9.8 | 5 months ago | 3 months ago |
|
|
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution | Critical 10.0 | 4 months ago | 3 months ago |
|
|
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass | Critical 9.8 | 4 months ago | 3 months ago |
|
|
vm2 is Vulnerable to Sandbox Breakout Through Promise Species | Critical 10.0 | 4 months ago | 3 months ago |
|
|
vm2 has a Sandbox Escape issue | Critical 10.0 | 4 months ago | 3 months ago |
|
|
NodeVM observability builtins leak host process and HTTP request data | Medium Risk 6.0 | 4 months ago | 3 months ago |
|
|
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain | High Risk 8.6 | 4 months ago | 3 months ago |
|
|
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks | High Risk 8.7 | 4 months ago | 3 months ago |
|
|
NodeVM network builtin exclusions bypass via internal _http_client and _http_server | High Risk 8.6 | 4 months ago | 3 months ago |
Page 1