Vulnerabilities

Last updated 3 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
vm2 vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process High Risk 8.6 8 hours ago 8 hours ago
vm2 vm2: NodeVM custom resolution bypasses external path boundaries Critical 10.0 8 hours ago 8 hours ago
vm2 vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary Critical 10.0 9 hours ago 8 hours ago
vm2 vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix Critical 10.0 9 hours ago 9 hours ago
vm2 vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process High Risk 8.6 9 hours ago 9 hours ago
vm2 vm2: Sandbox Escape (NodeVM) Critical 10.0 9 hours ago 9 hours ago
vm2 vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM High Risk 7.1 9 hours ago 9 hours ago
vm2 vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack Medium Risk 5.8 9 hours ago 9 hours ago
vm2 vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting Medium Risk 5.8 9 hours ago 9 hours ago
vm2 vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit Critical 9.0 9 hours ago 9 hours ago
vm2 vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool Critical 10.0 9 hours ago 9 hours ago
vm2 vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Medium Risk 6.8 4 days ago 4 days ago
vm2 vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts High Risk 8.6 4 days ago 4 days ago
vm2 vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical 9.9 4 days ago 4 days ago
vm2 vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical 9.8 4 days ago 4 days ago
vm2 vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Medium Risk 4.0 4 days ago 4 days ago
vm2 vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection Critical 10.0 4 days ago 4 days ago
vm2 vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes High Risk 8.5 4 days ago 4 days ago
vm2 vm2 allows a sandboxed plugin to execute native code through `node:sqlite` Critical 9.9 4 days ago 4 days ago
vm2 vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical 9.0 4 days ago 4 days ago
vm2 vm2 NodeVM can replace the host process TLS trust store Critical 10.0 4 days ago 4 days ago
vm2 vm2 crypto builtin loads attacker native code through setEngine Critical 9.9 4 days ago 4 days ago
vm2 vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted Medium Risk 4.2 4 days ago 4 days ago
vm2 vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical 9.9 4 days ago 4 days ago
vm2 vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package Critical 9.9 4 days ago 4 days ago
vm2 vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical 10.0 4 days ago 4 days ago
vm2 vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` Medium Risk 5.3 5 months ago 18 days ago
vm2 vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass High Risk 7.5 1 month ago 18 days ago
vm2 vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter Low Risk 3.0 4 months ago 18 days ago
vm2 vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) Critical 10.0 1 month ago 18 days ago
vm2 vm2 Sandbox Escape vulnerability Critical 9.8 3 years ago 26 days ago
vm2 vm2 vulnerable to Inspect Manipulation Medium Risk 5.3 3 years ago 26 days ago
vm2 vm2 vulnerable to sandbox escape Critical 9.8 3 years ago 26 days ago
vm2 vm2 before 3.6.11 vulnerable to sandbox escape High Risk 8.3 4 years ago 26 days ago
vm2 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical 9.8 1 month ago 1 month ago
vm2 vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike High Risk 8.0 1 month ago 1 month ago
vm2 VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE Critical 9.9 1 month ago 1 month ago
vm2 vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE Critical 10.0 4 months ago 2 months ago
vm2 vm2 Sandbox Escape vulnerability Critical 9.8 3 years ago 2 months ago
vm2 Sandbox bypass in vm2 Critical 9.8 4 years ago 3 months ago
vm2 Prototype Pollution in vm2 Critical 9.8 4 years ago 3 months ago
vm2 VM2 Has a WASM Sandbox Escape Critical 9.8 5 months ago 3 months ago
vm2 NodeVM builtin denylist bypass via process and inspector/promises allows host code execution Critical 10.0 4 months ago 3 months ago
vm2 vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass Critical 9.8 4 months ago 3 months ago
vm2 vm2 is Vulnerable to Sandbox Breakout Through Promise Species Critical 10.0 4 months ago 3 months ago
vm2 vm2 has a Sandbox Escape issue Critical 10.0 4 months ago 3 months ago
vm2 NodeVM observability builtins leak host process and HTTP request data Medium Risk 6.0 4 months ago 3 months ago
vm2 vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain High Risk 8.6 4 months ago 3 months ago
vm2 vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks High Risk 8.7 4 months ago 3 months ago
vm2 NodeVM network builtin exclusions bypass via internal _http_client and _http_server High Risk 8.6 4 months ago 3 months ago