Product
The vm2 sandboxing library fails to properly secure the 'node:test' builtin module in Node.js 24+, allowing an attacker to escape the sandbox via a double-prefix require and execute arbitrary host code.