Skip to content

Vulnerable CachedDataOptions in API

High
laverdet published GHSA-2jjq-x548-rhpv Sep 29, 2022

Package

npm isolated-vm (npm)

Affected versions

<= 4.3.6

Patched versions

None

Description

Impact

If the untrusted v8 cached data is passed to the API through CachedDataOptions, the attackers can bypass the sandbox and run arbitrary code in the nodejs process.

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-39266

Weaknesses

No CWEs