Prototype Pollution in vm2
Critical severity
GitHub Reviewed
Published
Oct 19, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 18, 2021
Reviewed
Oct 19, 2021
Published to the GitHub Advisory Database
Oct 19, 2021
Last updated
Feb 1, 2023
This affects the package vm2 before 3.9.4. Prototype Pollution attack vector can lead to sandbox escape and execution of arbitrary code on the host machine.
References