Five Critical vm2 Vulnerabilities Grant Instant Node.js Host RCE
ID: 3933280a-7a10-58e9-bcf7-c3230af98848
STIX ID: report--3933280a-7a10-58e9-bcf7-c3230af98848
Feed Name: securityonline.info
This report discloses five critical vulnerabilities in the vm2 Node.js sandbox (impacting versions through 3.11.3) that permit sandboxed scripts to escape and achieve remote code execution on the host via multiple vectors (builtin denylist bypass, JSPI-backed Promise species bypass, a patch-bypass allowing nested VMs, and prototype/property manipulation). All issues carry top severity (CVSS 9.8–10.0), there are no reliable configuration mitigations, and the vendor remediation is upgrading to vm2 version 3.11.4 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
