Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library

Discussion in 'News Aggregator' started by The Hacker News, 8 Apr 2023.

  1. The maintainers of the vm2 JavaScript sandbox module have shipped a patch to address a critical flaw that could be abused to break out of security boundaries and execute arbitrary shellcode. The flaw, which affects all versions, including and prior to 3.9.14, was reported by researchers from South Korea-based KAIST WSP Lab on April 6, 2023, prompting vm2 to release a fix with version 3.9.15 on

    Continue reading...
     

Share This Page

Loading...