Skip to content

vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution

Critical severity GitHub Reviewed Published May 1, 2026 in patriksimek/vm2 • Updated May 14, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts