PT-2021-15533 · Vm2 · Vm2

Abdullah Alhamdan

+1

·

Published

2021-10-18

·

Updated

2021-11-04

·

CVE-2021-23449

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.9.4
Description The issue is related to a Prototype Pollution attack vector, which can lead to sandbox escape and execution of arbitrary code on the host machine. This allows for the execution of arbitrary code on the host machine, posing a significant security risk.
Recommendations For versions prior to 3.9.4, update to version 3.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vm2 package until a patch is applied.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23449
GHSA-RJF2-J2R6-Q8GR
SNYK-JS-VM2-1585918

Affected Products

Vm2