eclipse-thingweb / eclipse-thingweb/node-wot
Critical security vulnerability for VM2
Open
cli
security
- Dominant language
- TypeScript
- Stars
- 192
- Forks
- 100
- Avg merge
- 3d 2h
- Merged PRs (30d)
- 6
Description
Today we have a new critical alert in our security report. VM2 has been found vulnerable to [escaping the sandbox](https://github.com/eclipse-thingweb/node-wot/security/dependabot/73). As described [here](https://github.com/patriksimek/vm2/issues/533), the main maintainer is not willing to fix the issue (because it would cause a major refactoring of the whole library). We now have to decide whether to migrate to [isolate-vm](https://github.com/laverdet/isolated-vm) (but in my understanding is not really a 1-1 mapping with vm2) or to change the scope of the CLI (as we were questioning it already).
Contributor guide
Assessment
This issue has not been assessed yet.