Critical vm2 sandbox bug lets attackers execute code on hosts

Source: BleepingComputer  ·  Category: Security News — Technology


A critical vulnerability in Node.js sandboxing library vm2 allows arbitrary code execution on the host system, breaking sandbox isolation. Law firms using vm2 in applications or development environments must upgrade immediately or disable the library; this is a zero-day-equivalent risk.

→ Read the full article

Read more