This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
- https://snyk.io/vuln/SNYK-JS-VM2-1585918
- https://github.com/mrhenrike/Hacking-Cheatsheet
- https://github.com/w181496/Web-CTF-Cheatsheet