← Back to browse · API

CVE-2022-36067

Severity
CRITICAL
CVSS
10.0
EPSS
0.47868
Risk score
56.75
CISA KEV
No
PoC
No
Published
2022-09-06
Modified
2025-04-22
First seen
2026-08-07
Aliases
EUVD-2022-6880, GHSA-MRGP-MRHC-5JRQ
Products
patriksimek:vm2 < 3.9.11
Sources
euvd EUVD-2022-6880

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

References