You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since middle July there is a critical issue in sandbox vm2 in NodeJs GHSA-cchq-frgv-rjh5
The Developer set the Project to discontinued and recommend migrating to an other librabry https://github.com/patriksimek/vm2
Description:
Use in Rocketchat:
apps/meteor/app/integrations/server/api/api.js
import { VM, VMScript } from 'vm2';
Are there any plans to replace this library?
The text was updated successfully, but these errors were encountered:
vm2 is still available to be used until the next major version of rocket.chat as the issue can only be abused by someone with admin access, but you can already disable it completely with envvars.
Our apps-engine also depends on vm2 and we have separate work happening there to replace it completely as well as temporary solutions available to block it from being used.
Since middle July there is a critical issue in sandbox vm2 in NodeJs
GHSA-cchq-frgv-rjh5
The Developer set the Project to discontinued and recommend migrating to an other librabry
https://github.com/patriksimek/vm2
Description:
Use in Rocketchat:
apps/meteor/app/integrations/server/api/api.js
Are there any plans to replace this library?
The text was updated successfully, but these errors were encountered: