LOWCVSS 10.0 · CRITICAL
Signal is active with 1 mentions in latest observed window
Immediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.