Skip to content

Secure vm process  #14

@risenW

Description

@risenW

Executing code with the Nodejs VM module has many known security vulnerabilities, and we need to address them before any major release.

This tool might help: https://github.com/patriksimek/vm2

See also:
nodejs/node#40718
https://pwnisher.gitlab.io/nodejs/sandbox/2019/02/21/sandboxing-nodejs-is-hard.html
https://github.com/laverdet/isolated-vm

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions