Liran Tal
1 min readDec 9, 2018

--

Thanks for the snyk mention Alberto!

FYI that Node’s VM module is not a security sandbox and globals and variables passing to it can manipulate external state and objects.

Hope you’re snyked-care-of and would be happy to hear how is it going for you and if there’s any feedback you’d like to pass on.

p.s goodluck with LogRocket!

--

--

Liran Tal
Liran Tal

Written by Liran Tal

🥑Developer Advocate @snyksec | @NodeJS Security WG | 🛰️ @jsheroes ambassador | Author of Essential Node.js Security | ❤️ #opensource #web ☕🍕🎸

No responses yet