Critical vm2 Vulnerabilities Enable Arbitrary Code Execution Attacks
ID: 37597d63-e3a9-55dd-a32a-a2456d632129
STIX ID: report--37597d63-e3a9-55dd-a32a-a2456d632129
Feed Name: Cyber Press
Multiple critical sandbox-escape vulnerabilities were disclosed in the widely used Node.js sandbox library vm2, enabling sandboxed code to obtain host-realm objects (e.g., Function.prototype) and execute arbitrary commands on the host (RCE). Eleven advisories/CVEs are listed with affected and patched versions; most issues have fixes in vm2 3.11.0/3.11.1 but two CVEs remained unpatched at disclosure. Public proof-of-concept exploits exist for several issues, and the report recommends immediate upgrades, monitoring for additional patches, and considering more hardened alternatives such as isolated-vm or Deno’s permission model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
