vm2 Sandbox escape vulnerability
CVE-2023-29199

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
14 April 2023

What is CVE-2023-29199?

The vm2 library for Node.js suffers from a vulnerability within its source code transformer related to exception sanitization logic. This flaw allows attackers to bypass the handleException() function and expose unsanitized host exceptions that might lead to a sandbox escape. If exploited, a threat actor could run arbitrary code within the host environment, compromising system security. The issue has been rectified in version 3.9.16 of vm2, making it imperative for users to update their installations to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

vm2 < 3.9.16

References

EPSS Score

24% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.