Description
The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.
Remediation
References
https://github.com/patriksimek/vm2/commit/532120d5cdec7da8225fc6242e154ebabc63fe4d
https://snyk.io/vuln/SNYK-JS-VM2-2309905
Related Vulnerabilities
CVE-2021-4245 Vulnerability in npm package rfc6902
CVE-2023-29511 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2023-26133 Vulnerability in npm package progressbar.js
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-35517 Vulnerability in maven package org.apache.commons:commons-compress