npm Alert
2768Warning Date
Severity Level
Warning Number
Target Sector
8 April, 2023
● Critical
2023-5531
All
npm has released a security update to address a vulnerability in the following product:
- vm2 sandbox library
- 3.9.14 and older
An attacker could exploit these vulnerabilities by doing the following:
- Sandbox Bypass
- Arbitrary Remote Code Execution
The CERT team encourages users to review npm security advisory and apply the necessary update: