Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):
erincandescent@queer.af ("Erin 💽") wrote:
Update: I went and read the documentation on the node:vm package and one of the first things it says - in bold, red text - is:
The node:vm module is not a security mechanism. Do not use it to run untrusted code.
Indeed, its not a sandbox at all (and is not intended as one!)