CVE-2023-29199
Summary
| CVE | CVE-2023-29199 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-14 19:15:00 UTC |
| Updated | 2023-04-25 15:14:00 UTC |
| Description | There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Vm2 Project |
Vm2 |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378431 vm2 NPM Package Remote Code Execution (RCE) Vulnerability (GHSA-xj72-wvfv-8985)