CVE-2021-23449

CRITICAL9.8EPSS 2.2%

Prototype Pollution in vm2

發布日:2021/10/19修改日:2026/3/13

描述

This affects the package vm2 before 3.9.4. Prototype Pollution attack vector can lead to sandbox escape and execution of arbitrary code on the host machine.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(7)