Security News > 2023 > April > Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library
data:image/s3,"s3://crabby-images/50434/5043434eff744d086afc10728d3bb20b712896ee" alt="Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library"
The maintainers of the vm2 JavaScript sandbox module have shipped a patch to address a critical flaw that could be abused to break out of security boundaries and execute arbitrary shellcode.
The flaw, which affects all versions, including and prior to 3.9.14, was reported by researchers from South Korea-based KAIST WSP Lab on April 6, 2023, prompting vm2 to release a fix with version 3.9.15 on Friday.
"A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox," vm2 disclosed in an advisory.
Vm2 is a popular library that's used to run untrusted code in an isolated environment on Node.js.
KAIST security researcher Seongil Wi has also made available two different variants of a proof-of-concept exploit for CVE-2023-29017 that get around the sandbox protections and allow the creation of an empty file named "Flag" on the host.
The disclosure comes almost six months after vm2 resolved another critical bug that could have been weaponized to perform arbitrary operations on the underlying machine.
News URL
https://thehackernews.com/2023/04/researchers-discover-critical-remote.html
Related news
- Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF Injection (source)
- Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution (source)
- Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution (source)
- Rsync vulnerabilities allow remote code execution on servers, patch quickly! (source)
- Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager (source)
- Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks (source)
- New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution (source)
- Critical flaws in Mongoose library expose MongoDB to data thieves, code execution (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-06 | CVE-2023-29017 | Unspecified vulnerability in VM2 Project VM2 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. | 9.8 |