peter bassill · operator
$ cve CVE-2023-37466 JSON

CVE-2023-37466

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside the context of vm2 sandbox. Version 3.10.0 contains a patch for the issue.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.87% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2023-07-14
Last modified2026-06-17

Affected (1)

VendorProduct
vm2 projectvm2

References

→ the Explorer  ·  watch your stack  ·  NVD