logo

Patch Released for Critical vm2 Sandbox Escape Vulnerability

ID: 89e9ebbb-37ac-5a5f-a320-d4a96a885722

STIX ID: report--89e9ebbb-37ac-5a5f-a320-d4a96a885722

Feed Name: FortiGuard Threat Signals

Threat Score
80/100

Date Published: 2025-07-24

Date Updated: 2026-07-28

...
...

This advisory reports multiple critical sandbox escape vulnerabilities in the vm2 Node.js module (CVE-2023-29017, CVE-2023-29199, CVE-2023-30547) with CVSS scores of 9.8 that can allow remote code execution from within a sandbox; PoCs are publicly available and fixes were released (vm2 3.9.16 and 3.9.17), so users should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.