🚀 Join our AI Wargame at Black Hat Asia and our Workshop + Wargame at NDC Sydney .


Coming Soon: Write up on vm2 and JS Sandboxing

02/06/2026

The maintainers of vm2 have been honest about its limitations.

They have been explicit that new sandbox bypasses are likely to occur and that vm2 should not be relied on as a sole security control.

It is a welcome trend to see maintainers openly discuss the limitations and security assumptions of their projects.

Later this month, we’ll be publishing a write-up on vm2 and the security implications of JavaScript sandboxes. Stay tuned.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more