PT-2023-32964 · Vm2+3 · Vm2+3
Published
2023-09-15
·
Updated
2023-09-15
CVSS v3.1
7.6
High
| Vector | AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions up to 3.9.19
Directus versions prior to 10.6.0
Description
The issue allows attackers to bypass Promise handler sanitization in vm2, enabling them to escape the sandbox and execute arbitrary code. This specifically affects the "Run Script" operation in Directus flows, where code can escape the sandbox and run in the main Node.js context.
Recommendations
For vm2 versions up to 3.9.19, update to a version that replaces
vm2 with isolated-vm, such as Directus version 10.6.0.
For Directus versions prior to 10.6.0, update to version 10.6.0 to replace vm2 with isolated-vm.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directus
Node.Js
Isolated-Vm
Vm2