A popular NPM package called Pac-Resolver for Node.js has been fixed for a high-severity remote code execution vulnerability. The flaw, tracked as CVE-2021-23406, has a severity rating of 8.1 on the CVSS vulnerability scoring system. The fix is simple: use a real sandbox instead of the VM built-in module, says Tim Perry. Red Hat, in an independent advisory, said the vulnerable package is shipped with its Advanced Cluster Management for Kubernetes product.”]
Source: https://thehackernews.com/2021/09/critical-bug-reported-in-npm-package.html