vm2 Sandbox Library Exposes Three Critical CVSS 10.0 Vulnerabilities in a 12‑Bug Sweep
Security researchers dissected vm2, the popular Node.js sandbox library, and disclosed twelve vulnerabilities—including three CVSS 10.0 flaws that allow unchecked require, WebAssembly JSPI escape, and deny‑list bypass—prompting immediate upgrades and mitigation steps for all users.
