Security researchers disclose multiple critical vulnerabilities affecting the Node.js sandboxing library vm2. Several reports state that attackers can exploit these flaws to escape the vm2 sandbox and execute arbitrary code on the underlying host system, potentially compromising applications that run untrusted JavaScript using vm2. The library is described as an open-source component used to isolate untrusted code by intercepting and proxying JavaScript objects, with the intent that sandboxed code cannot access resources on the host. The disclosures characterize the issues as critical and indicate they are relevant to environments where vm2 is used to run third-party or otherwise untrusted JavaScript. Across the sources, the core concern is that sandbox boundaries can be bypassed through crafted inputs or execution paths, enabling code execution beyond the intended isolation. While specific technical details and scope are not fully reproduced in the provided excerpts, both sources agree on the overall risk: vm2’s sandboxing protections can fail under attack, leading to host-level code execution on vulnerable setups.
Multiple vm2 vulnerabilities could allow sandbox escape and arbitrary code execution
Security researchers disclose multiple critical vulnerabilities affecting the Node.js sandboxing library vm2. Several reports state that attackers can exploit these flaws to escape the vm2 sandbox and...
- vm2 is a Node.js library used to run untrusted JavaScript code in a sandbox.
- Reported vulnerabilities are described as critical and security-sensitive.
- Exploitation can allow breaking out of the vm2 sandbox.
- Successful attacks can enable arbitrary code execution on the host system.
- The disclosures warn these issues affect systems using vm2 to isolate untrusted code.
A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. vm2 is an open-source library used to run untrusted JavaScript code inside a secure sandbox by intercepting and proxying JavaScript objects to prevent sandboxed code from accessing the host
3 months agoA critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system. [...]
3 months ago
Liverpool in talks with PSG over Bradley Barcola amid price and transfer uncertainty
Liverpool are moving through negotiations to sign Paris Saint-Germain winger Bradley Barcola, their top summer target, a...
Matt LaFleur expects Josh Jacobs to remain on Packers roster amid pending charges
Packers head coach Matt LaFleur says he fully anticipates running back Josh Jacobs will remain on the team despite Jacob...
Fever beat Liberty as Clark and Mitchell power win
The Indiana Fever defeat the New York Liberty 106-92 on Tuesday night, with Caitlin Clark scoring 22 points and adding 1...