← back
CVE-2022-36067criticalCWE-913

vm2 vulnerable to Sandbox Escape before v3.9.11

60Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 10epss 48%
from disclosure to weapon36 days
Published on NVDSep 6
1st PoC+36d
exploitation probability
48%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
patriksimek · vm2
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.