← Back to browse · API

CVE-2023-30547

Severity
CRITICAL
CVSS
9.8
EPSS
0.72087
Risk score
64.43
CISA KEV
No
PoC
Yes
Published
2023-04-17
Modified
2025-02-05
First seen
2026-08-07
Aliases
EUVD-2023-1268, GHSA-CH3R-J5X3-6Q2M
Products
patriksimek:vm2 < 3.9.17
Sources
euvd EUVD-2023-1268
github 3a50fa48b29b86334a386ca7|CVE-2023-30547

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

References