TooTallNate / node-proxy-agent

Maps proxy protocols to `http.Agent` implementations
285 stars 69 forks source link

CVE-2023-29017: Critical vulnerability in vm2 dependancy [sandbox escape] #80

Closed aaronwilson-1 closed 1 year ago

aaronwilson-1 commented 1 year ago

The dependancy chain needs to be updated to apply the patch for this critical vulnerability.

https://github.com/advisories/GHSA-7jxr-cg7f-gpgv

proxy-agent -> pac-proxy-agent -> pac-resolver -> vm2

TooTallNate commented 1 year ago

The semver ranges on all those dependencies are already loose enough to pick up the fixed version of vm2. Please update your lockfile.