GitLab's Threat Research Group has identified a critical sandbox escape vulnerability (CVSS 3.1: 10.0) in the vm2 Node.js sandboxing library, where certain configurations allow untrusted code to execute unsafely on the host system. Developers are urged to upgrade to vm2 Version 3.11.7 and implement additional security measures, including restricting configuration settings to mitigate risks from similar vulnerabilities.