PT-2022-9410 · Vm2 · Vm2

Abdullah Alhamdan

+1

·

Published

2022-02-11

·

Updated

2022-02-22

·

CVE-2021-23555

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.9.6
Description The issue allows for Sandbox Bypass via direct access to host error objects generated by node internals during generation of stacktraces. This can lead to execution of arbitrary code on the host machine.
Recommendations For versions prior to 3.9.6, update to version 3.9.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the vm2 package until a patch is applied.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23555
GHSA-6PW2-5HJV-9PF7
SNYK-JS-VM2-2309905

Affected Products

Vm2