Using Outdated vm2 Versions with Known Vulnerabilities
Applications use outdated vm2 versions containing known sandbox escape vulnerabilities (CVE-2023-29017, CVE-2023-30547, CVE-2023-32313, CVE-2023-37466). The vm2 library has history of critical security issues where attackers exploit prototype pollution, constructor manipulation, or proxy object weaknesses to break sandbox isolation. Organizations fail to monitor vm2 security advisories or update dependencies promptly. Applications deployed months or years ago continue running vulnerable vm2 versions without security patches. Package-lock.json pins old vm2 versions preventing automatic updates. Even with regular dependency updates, vm2's frequent security issues create ongoing risk where new exploits emerge faster than patches can be deployed.