CVE-2023-37903: critical vulnerability in patriksimek vm2
Sandbox Escape in vm2
Published · Updated
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 4.2%
from disclosure to weapon107 days
Published on NVDJul 21
1st PoC+107d
exploitation probability
4.2%top 9% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
patriksimek · vm2public PoCs found — 1
githubgithub.com/7h3h4ckv157/CVE-2023-37903★ 9⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — patriksimek vm2
In the same product, most dangerous first.
CVE-2023-30547CRITICALSandbox Escape in vm2EPSS 72.1%CVE-2023-29017CRITICALvm2 Sandbox Escape vulnerabilityEPSS 63.2%CVE-2022-36067CRITICALvm2 vulnerable to Sandbox Escape before v3.9.11EPSS 47.9%CVE-2023-32314CRITICALSandbox EscapeEPSS 8.1%CVE-2023-37466CRITICALvm2 Sandbox Escape vulnerabilityEPSS 3.9%CVE-2023-29199CRITICALvm2 Sandbox escape vulnerabilityEPSS 3.9%