Critical remote code execution in vm2, a widely used Node.js sandbox library

- GitLab: 36 events in the last 90 days
- Previous: 6 days earlier · GitLab compliance frameworks: Adhere to SOC 2 in minutes
What happened
GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.
Summary assembled by rule from the sources below