The Hacker News - Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library
The maintainers of the vm2 JavaScript sandbox module have shipped a patch to address a critical flaw that could be abused to break out of security boundaries and execute arbitrary shellcode. The flaw, which affects all versions, including and prior to 3.9.14, was reported by researchers from South Korea-based KAIST WSP Lab on April 6, 2023, prompting vm2 to release a fix with version 3.9.15 on
from The Hacker News https://thehackernews.com/2023/04/researchers-discover-critical-remote.html
from The Hacker News https://thehackernews.com/2023/04/researchers-discover-critical-remote.html
Comments
Post a Comment