PT-2023-3541 · Node.Js · Vm2
Seunghyun Lee
+1
·
Published
2023-07-06
·
Updated
2026-05-25
·
CVE-2023-37466
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.10.0
Description
vm2 is an advanced sandbox for Node.js. A flaw in the sanitization of the
Promise handler allows the @@species accessor property to be bypassed. This enables attackers who already have arbitrary code execution primitives within the sandbox context to escape the isolated environment and execute arbitrary code on the host system, potentially leading to remote code execution. The project maintenance has been discontinued, and the library is not recommended for production use.Recommendations
Update to version 3.10.0.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2