node-wot
node-wot copied to clipboard
Critical security vulnerability for VM2
Today we have a new critical alert in our security report. VM2 has been found vulnerable to escaping the sandbox. As described here, the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to isolate-vm (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).