json-merger icon indicating copy to clipboard operation
json-merger copied to clipboard

Two security vulnerabilities with vm2 <= 3.9.17

Open jwkellyiii opened this issue 2 years ago • 1 comments

There are two critical security vulnerabilities with vm2 <= 3.9.17. vm2 has released 3.9.19. Could we get a version bump that includes this update?

  1. vm2 Sandbox Escape vulnerability - https://github.com/advisories/GHSA-whpj-8f3w-67p5
  2. vm2 vulnerable to Inspect Manipulation - https://github.com/advisories/GHSA-p5gc-c584-jj6v

jwkellyiii avatar May 26 '23 15:05 jwkellyiii

VM2 has been deprecated and remains vulnerable. See note from author recommending isolated-vm as a replacement.
image

Marzz3 avatar Aug 25 '23 15:08 Marzz3