VYPR

Vm2

by Patriksimek

npm: vm2

Source repositories

CVEs (41)

  • CVE-2023-32313MedMay 15, 2023
    risk 0.28cvss 5.3epss 0.01

    vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a threat actor can edit options for the…

Page 3 of 3