CVE-2021-23449

CRITICAL9.8EPSS 2.2%

Prototype Pollution in vm2

Published: 10/19/2021Modified: 3/13/2026

Description

This affects the package vm2 before 3.9.4. Prototype Pollution attack vector can lead to sandbox escape and execution of arbitrary code on the host machine.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (7)