A remote code execution vulnerability (CVE-2022-36067) has been identified in vm2 sandbox versions prior to 3.9.11.
vm2 is a commonly used software testing framework. The popular Javascript sandbox library has at least 16 million monthly downloads.
Exploitation of this vulnerability could allow a malicious actor to bypass the sandbox protections to gain remote code execution rights on the host running the sandbox and perform unauthorised actions.