node-wot icon indicating copy to clipboard operation
node-wot copied to clipboard

Critical security vulnerability for VM2

Open relu91 opened this issue 1 year ago • 1 comments

Today we have a new critical alert in our security report. VM2 has been found vulnerable to escaping the sandbox. As described here, the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to isolate-vm (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).

relu91 avatar Jul 14 '23 08:07 relu91