Critical vm2 sandbox vulnerability allows credential theft and socket hijacking
A critical vulnerability in the Node.js sandbox library vm2 allows sandboxed code to access the host's global network agents. This enables attackers to intercept network requests and steal sensitive authorization headers like Bearer tokens. The flaw affects vm2 versions 3.11.3 through 3.11.6 and carries the maximum CVSS score of 10.0. A proof-of-concept exploit is available via the official regression test suite. Users must upgrade to version 3.11.7 or newer to mitigate the issue.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in