Skip to content

Critical security vulnerability for VM2 #1035

Open
@relu91

Description

@relu91

Today we have a new critical alert in our security report. VM2 has been found vulnerable to escaping the sandbox. As described here, the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to isolate-vm (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).

Metadata

Metadata

Assignees

No one assigned

    Labels

    cliIssues with the command line interfacesecurityIssues related to security vulnerability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions