← Back to events
ActiveTech

Critical remote code execution in vm2, a widely used Node.js sandbox library

Photo: GitLab Blog

What happened

GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.

Summary assembled by rule from the sources below

Why it's spreading

Sources