You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass handleException() and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.16 of vm2.
mend-for-github-combot
changed the title
CVE-2023-29199 (Medium) detected in vm2-3.9.3.tgz
CVE-2023-29199 (High) detected in vm2-3.9.3.tgz
Apr 17, 2023
mend-for-github-combot
changed the title
CVE-2023-29199 (High) detected in vm2-3.9.3.tgz
CVE-2023-29199 (Critical) detected in vm2-3.9.3.tgz
Jun 2, 2023
CVE-2023-29199 - Critical Severity Vulnerability
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Securely!
Library home page: https://registry.npmjs.org/vm2/-/vm2-3.9.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/vm2/package.json
Dependency Hierarchy:
Found in HEAD commit: ba236fd18ec3e6450d68d675bce1609d2e5d3230
Found in base branch: main
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass
handleException()
and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version3.9.16
ofvm2
.Publish Date: 2023-04-14
URL: CVE-2023-29199
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-xj72-wvfv-8985
Release Date: 2023-04-14
Fix Resolution (vm2): 3.9.16
Direct dependency fix Resolution (juicy-chat-bot): 0.7.1
The text was updated successfully, but these errors were encountered: