Junglewise Threat Intelligence

CVE-2023-37466: vm2 Sandbox Escape via Promise handler bypass

CVE-2023-37466 · Severity: low · CVSS 3.1 · Published 2023-07-13

Technologies: vm2 (npm). Vendors: npm.

Executive brief

vm2 is a popular Node.js library that creates isolated virtual machine environments to safely execute untrusted code. This vulnerability allows attackers who can run code within the vm2 sandbox to escape that isolation and execute arbitrary commands on the host system, completely bypassing the intended security boundary.

Technical details

The vulnerability is a sandbox escape (CWE-94) in vm2 versions up to 3.9.19 caused by improper sanitization of Promise handler callbacks. An attacker with arbitrary code execution inside the vm2 sandbox can exploit this weakness to escape the isolation and gain code execution on the host. The attack requires the attacker to already have execution capability within the sandbox context but does not require network access, authentication, or user interaction beyond that. The issue is triggered by crafted Promise handlers that bypass the sandbox's security checks. Version 3.10.0 and later include fixes; no workarounds are available for affected versions.

Affected products

  • npm vm2 up to 3.9.19

Timeline

  • 2023-07-13: disclosed
  • 2023-07-13: patched: Fixed in version 3.10.0

References

Related threats