newsGitLab BlogTrust 72 · OutletPublished 10d agoLive · 8d ago
Critical remote code execution in vm2, a widely used Node.js sandbox library
GitLab's Threat Research Group found a critical sandbox escape vulnerability in vm2, one of the most widely adopted Node.js sandboxing libraries. The vulnerability uses a configuration copied straight from vm2's own README. We found the flaw, rated CVSS 3.1: 10.0, critical, using our own AI automated tools. Anyone running vm2 Version 3.11.6 or earlier with require.external turned on should treat this as directly exploitable. Once we found the vulnerability, we verif
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- PossiblePossibly related (embedding) · 60%rivet-dev/secure-exec →
- PossiblePossibly related (embedding) · 51%beelzebub-labs/beelzebub →
- PossiblePossibly related (embedding) · 49%Th0rgal/sandboxed.sh →
- PossiblePossibly related (embedding) · 49%vuphongle/oss-pr-reviewer →
- PossiblePossibly related (embedding) · 47%Nayjest/Gito →
