eclipse-thingweb / eclipse-thingweb/node-wot

Critical security vulnerability for VM2

Open
#1,035 1 comment 1 reaction 0 assignees View on GitHub
cli security
Dominant language
TypeScript
Stars
192
Forks
100
Avg merge
3d 2h
Merged PRs (30d)
6

Description

Today we have a new critical alert in our security report. VM2 has been found vulnerable to [escaping the sandbox](https://github.com/eclipse-thingweb/node-wot/security/dependabot/73). As described [here](https://github.com/patriksimek/vm2/issues/533), the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to [isolate-vm](https://github.com/laverdet/isolated-vm) (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.