Plan
active
Critical RCE (CVSS 10.0) in vm2 Node.js sandbox, patched in 3.11.7
- Platform/SRE — Skip
- CI/CD — Plan: Audit build scripts, custom GitHub Actions, and any Node.js-based pipeline tooling for vm2 usage; if found, update to 3.11.7 and disable require.external — the blog post describes a working exploit path (CVSS 10.0), so exposure is concrete even without a KEV entry. No forced deadline, but the publicly documented exploit makes this a near-term project, not a watch item.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.