Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical security vulnerability for VM2 #1035

Open
relu91 opened this issue Jul 14, 2023 · 1 comment
Open

Critical security vulnerability for VM2 #1035

relu91 opened this issue Jul 14, 2023 · 1 comment
Labels
cli Issues with the command line interface security Issues related to security vulnerability

Comments

@relu91
Copy link
Member

relu91 commented Jul 14, 2023

Today we have a new critical alert in our security report. VM2 has been found vulnerable to escaping the sandbox. As described here, the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to isolate-vm (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).

@relu91 relu91 added cli Issues with the command line interface security Issues related to security vulnerability labels Jul 14, 2023
@relu91
Copy link
Member Author

relu91 commented Aug 11, 2023

I want to note down that this affects CLI-only users, if you are using node-wot as a simple library dependency everything is fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cli Issues with the command line interface security Issues related to security vulnerability
Projects
None yet
Development

No branches or pull requests

1 participant