pm2 icon indicating copy to clipboard operation
pm2 copied to clipboard

vm2 critical vulnerability RCE the library will be discontinued ([email protected])

Open boxexchanger opened this issue 2 years ago • 6 comments

Overview

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.

Affected versions of this package are vulnerable to Remote Code Execution (RCE) such that handler sanitization can be bypassed, allowing attackers to escape the sandbox.

Introduced

[email protected] › @pm2/[email protected][email protected][email protected][email protected][email protected][email protected]

How to fix?

There is no fixed version for vm2.

Note:

According to the maintainer, the security issue cannot be properly addressed and the library will be discontinued.

References

GitHub Issue SNYK-JS-VM2-5772825

boxexchanger avatar Jul 14 '23 01:07 boxexchanger

https://github.com/TooTallNate/proxy-agents/issues/218

egaudry avatar Jul 14 '23 09:07 egaudry

The proxy-agent dependency just released a new version 6.3.0 that no longer depends on vm2: https://github.com/TooTallNate/proxy-agents/releases

mterrel avatar Jul 18 '23 16:07 mterrel

vm2 critical security issue - same as here: https://github.com/Unitech/pm2/issues/5643 Need this fixed ASAP for CI/CD Pipeline which recognizes this as a Critical risk

gabrielenosso avatar Jul 19 '23 12:07 gabrielenosso

The proxy-agent dependency just released a new version 6.3.0 that no longer depends on vm2: https://github.com/TooTallNate/proxy-agents/releases

Is there a way to update a project that uses vm2 to install the newer version of the dependent packages instead of the broken ones for the time vm2 itself doesn't update it?

cklat avatar Jul 24 '23 10:07 cklat

This critical vulnerability has existed for 9 months. Any intention to address this?

j1mmie avatar Jan 23 '24 21:01 j1mmie

This critical vulnerability has existed for 9 months. Any intention to address this?

What? So pm2 still hasn't addressed this yet? I wanted to start using it but first ran into #5642 and now this as well?

Chiroyce1 avatar Jan 26 '24 13:01 Chiroyce1