Back

CRITICAL

vm2 vulnerable to Sandbox Escape before v3.9.11

Published Sep 6, 2022

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 6, 2022
Updated Apr 22, 2025
Reserved Jul 15, 2022
CISA Vulnrichment
Updated Apr 22, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Sep 7, 2022
GHSA-MRGP-MRHC-5JRQ