Vulnerabilities > VM2 Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-11 | CVE-2021-23555 | Unspecified vulnerability in VM2 Project VM2 The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine. | 9.8 |
2021-10-18 | CVE-2021-23449 | Unspecified vulnerability in VM2 Project VM2 This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. | 10.0 |