vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside the context of vm2 sandbox.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-07-13T23:17:51.434Z

Updated: 2023-09-15T17:16:58.315Z

Reserved: 2023-07-06T13:01:36.997Z


Link: CVE-2023-37466

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-14T00:15:09.263

Modified: 2024-02-01T14:05:45.750


Link: CVE-2023-37466

JSON object: View

cve-icon Redhat Information

No data.

CWE