3.11.3
12 years ago
2 days ago
Known vulnerabilities in the vm2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection despite the recently introduced How to fix Arbitrary Code Injection? Upgrade | <3.11.2 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization through the Notes: This is a complementary fix for CVE-2026-44003 How to fix Improper Isolation or Compartmentalization? Upgrade | <3.11.2 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Symlink Attack via the How to fix Symlink Attack? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization through the How to fix Improper Isolation or Compartmentalization? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization through the How to fix Improper Isolation or Compartmentalization? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Information Exposure via the sandbox CallSite handling. An attacker can leak absolute host filesystem paths by causing How to fix Information Exposure? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Uncaught Exception through the How to fix Uncaught Exception? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection through the proxy trap methods in How to fix Arbitrary Code Injection? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection through the Note: Constructor access was partially blocked in version 3.10.5, but this bypasses the protection introduced there. How to fix Arbitrary Code Injection? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection through the How to fix Arbitrary Code Injection? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection through the How to fix Arbitrary Code Injection? Upgrade | <3.10.5 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Injection through the How to fix Arbitrary Code Injection? Upgrade | <3.11.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Control of Dynamically-Managed Code Resources due to the unsafe usage of the Note: This issue can be mitigated by migrating to 'isolated-vm' for stronger isolation based on V8 Isolates and using OS-level isolation (Docker, gVisor, Firecracker) instead of application-level sandboxes. How to fix Improper Control of Dynamically-Managed Code Resources? Upgrade | <3.10.2 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to insufficient checks which allow an attacker to escape the sandbox. Note: According to the maintainer, the security issue cannot be properly addressed and the library will be discontinued. How to fix Remote Code Execution (RCE)? Upgrade | <3.10.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Remote Code Execution (RCE) such that the Note: According to the maintainer, the security issue cannot be properly addressed and the library will be discontinued. How to fix Remote Code Execution (RCE)? Upgrade | <3.10.0 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Bypass by abusing an unexpected creation of a host object based on the maliciously crafted specification of How to fix Sandbox Bypass? Upgrade | <3.9.18 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | <3.9.18 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions due to allowing attackers to raise an unsanitized host exception inside How to fix Improper Handling of Exceptional Conditions? Upgrade | <3.9.17 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Escape. There exists a vulnerability in source code transformer (exception sanitization logic), allowing attackers to bypass How to fix Sandbox Escape? Upgrade | <3.9.16 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Escape due to improper handling of host objects passed to How to fix Sandbox Escape? Upgrade | <3.9.15 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the How to fix Arbitrary Code Execution? Upgrade | <3.9.10 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Bypass via indirect access to How to fix Sandbox Bypass? Upgrade | <3.9.11 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine. How to fix Sandbox Bypass? Upgrade | <3.9.6 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. PoC
How to fix Sandbox Bypass? Upgrade | <3.9.4 |
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Affected versions of this package are vulnerable to Sandbox Bypass. It is possible to trigger a How to fix Sandbox Bypass? Upgrade | <3.6.11 |