
Developer Tools
Critical vm2 sandbox flaw lets untrusted code break out to the host
A newly disclosed vm2 vulnerability can let sandboxed JavaScript escape to the host system under specific Node.js 25 conditions, and proof-of-concept exploit code is already public.
BleepingComputer
remote-code-executionvm2
