PT-2023-3541 · Node.Js · Vm2

Seunghyun Lee

+1

·

Published

2023-07-06

·

Updated

2026-05-25

·

CVE-2023-37466

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.10.0
Description vm2 is an advanced sandbox for Node.js. A flaw in the sanitization of the Promise handler allows the @@species accessor property to be bypassed. This enables attackers who already have arbitrary code execution primitives within the sandbox context to escape the isolated environment and execute arbitrary code on the host system, potentially leading to remote code execution. The project maintenance has been discontinued, and the library is not recommended for production use.
Recommendations Update to version 3.10.0.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-03752
CVE-2023-37466
GHSA-CCHQ-FRGV-RJH5

Affected Products

Vm2