Security: patriksimek/vm2
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
NodeVM custom resolution bypasses external path boundariesGHSA-5h3f-q97h-ccvc published
Sep 8, 2026 by patriksimekCritical -
Host Promise rejection from an exposed constructor can terminate the vm2 host processGHSA-2v2p-6j97-cjg9 published
Sep 8, 2026 by patriksimekHigh -
NodeVM zlib Buffers expose pooled host memory across the VM boundaryGHSA-489w-w794-jq94 published
Sep 8, 2026 by patriksimekCritical -
Sandbox escape to host RCE via nullish this-receiver on non-strict host functionGHSA-j89j-5m6r-cr2q published
Sep 3, 2026 by patriksimekCritical -
NodeVM crypto sanitizer exposes process-wide crypto.setFipsGHSA-x3v6-43hc-82mc published
Sep 3, 2026 by patriksimekHigh -
Sandbox escape to host RCE in `NodeVM`: the dangerous-builtins denylist blocks `cluster`/`worker_threads`/`vm`/etc. but omits `child_process`, so `require:{builtin:['*']}` yields direct command executionGHSA-pq68-rvw4-xp4r published
Sep 3, 2026 by patriksimekCritical -
Sandbox escape in `VM`/`NodeVM`: a host-realm Promise's rejection sanitizer is bypassed via `Symbol.species` hijack and a missing `onRejected` handler, delivering the raw host rejection value to the sandboxGHSA-6454-5x88-m6jw published
Sep 3, 2026 by patriksimekCritical -
vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stackGHSA-r273-hxvj-fxhp published
Aug 27, 2026 by patriksimekModerate -
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuitGHSA-x965-fc75-jpqh published
Aug 27, 2026 by patriksimekCritical -
NodeVM nesting guard accepts array-shaped require and permits host RCEGHSA-8hr7-r645-pc6w published
Aug 24, 2026 by patriksimekCritical