Junglewise Threat Intelligence

CVE-2023-29199: vm2 Sandbox escape in exception sanitization

CVE-2023-29199 · Severity: low · CVSS 3.1 · Published 2023-04-12

Technologies: Patriksimek Vm2. Vendors: npm.

Executive brief

vm2 is a JavaScript sandbox library used to safely execute untrusted code in isolation. A vulnerability in its exception handling allows attackers to bypass the sandbox protections and execute arbitrary code with full access to the host system. An attacker can exploit this remotely without authentication to achieve complete system compromise.

Technical details

The vulnerability exists in the source code transformer's exception sanitization logic (handleException function) in vm2 versions up to 3.9.15. Attackers can craft malicious JavaScript code that triggers an exception, bypassing the exception sanitization logic to leak unsanitized host exceptions. These leaked exceptions expose internal host context information that can be leveraged to escape the sandbox and execute arbitrary code in the host context with no authentication required. The vulnerability is remotely exploitable over the network. A patch is available in vm2 version 3.9.16.

Affected products

  • Patriksimek vm2 <=3.9.15

Timeline

  • 2023-04-12: disclosed
  • 2023-04-12: patched: version 3.9.16 released

References

Related threats