Sandbox Bypass Affecting vm2 package, versions <3.9.11
Snyk CVSS
Attack Complexity
Low
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
2.31% (90th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-VM2-3018201
- published 7 Sep 2022
- disclosed 7 Sep 2022
- credit Oxeye
Introduced: 7 Sep 2022
CVE-2022-36067 Open this link in a new tabHow to fix?
Upgrade vm2
to version 3.9.11 or higher.
Overview
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.
Affected versions of this package are vulnerable to Sandbox Bypass via indirect access to host.Object
during preparation of stacktraces, which can lead to execution of arbitrary code on the host machine.