Remote Code Execution (RCE) Affecting vm2 package, versions *


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature
EPSS
1.07% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-VM2-5772825
  • published12 Jul 2023
  • disclosed12 Jul 2023
  • creditSeungHyun Lee

Introduced: 12 Jul 2023

CVE-2023-37466  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

There is no fixed version for vm2.

Overview

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.

Affected versions of this package are vulnerable to Remote Code Execution (RCE) such that the Promise handler sanitization can be bypassed, allowing attackers to escape the sandbox.

Note:

According to the maintainer, the security issue cannot be properly addressed and the library will be discontinued.

CVSS Scores

version 3.1