CVE-2023-37466

CVSS 3.1 Score 10.0 of 10 (high)

Details

Published Jul 14, 2023
Updated: Feb 1, 2024
CWE ID 94

Summary

CVE-2023-37466 is a critical security vulnerability affecting vm2, an advanced Node.js virtual machine library. The flaw, present in versions up to 3.9.19, enables attackers to bypass Promise handler sanitization using the `@@species` accessor property. This bypass allows code execution outside the intended sandbox, posing a potential threat of remote code execution within the vm2 sandbox environment. The project maintenance has been discontinued, making it crucial for organizations using vm2 to either patch the issue or consider alternative solutions for their Node.js sandboxing needs.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share