vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
Source: The Hacker News · Category: Supply Chain
Dozen critical vulnerabilities in vm2 Node.js library enable sandbox escape and arbitrary code execution. If the firm uses vm2 to execute untrusted code (e.g., in legal automation tools or document processing), immediate patching or replacement required to prevent RCE.