CuraDevOps

tag: Nodejs · 1 items

2026-09-03 · GitLab Blog · source ↗ #security#nodejs#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Plan: Audit build scripts, custom GitHub Actions, and any Node.js-based pipeline tooling for vm2 usage; if found, update to 3.11.7 and disable require.external — the blog post describes a working exploit path (CVSS 10.0), so exposure is concrete even without a KEV entry. No forced deadline, but the publicly documented exploit makes this a near-term project, not a watch item.
  • Leader — Skip