{"id":"GHSA-g6w6-h933-4rc5","summary":"Soketi was exposed to Sandbox Escape vulnerability via vm2","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nAnyone who might have used Soketi with the `cluster` driver (or through PM2).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nGet the latest version of Soketi.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nNone. It's advised to upgrade to the latest version.\n\n### References\n_Are there any links users can visit to find out more?_\n- https://github.com/advisories/GHSA-cchq-frgv-rjh5\n- https://github.com/patriksimek/vm2/issues/533\n- https://github.com/Unitech/pm2/issues/5643\n","modified":"2023-08-03T19:44:52Z","published":"2023-08-03T19:44:52Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-08-03T19:44:52Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/soketi/soketi/security/advisories/GHSA-g6w6-h933-4rc5"},{"type":"WEB","url":"https://github.com/Unitech/pm2/issues/5643"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/issues/533"},{"type":"WEB","url":"https://github.com/soketi/soketi/pull/927"},{"type":"WEB","url":"https://github.com/soketi/soketi/commit/de12bff706c0d62e6a57dc1c7be3c4f014d0093a"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cchq-frgv-rjh5"},{"type":"PACKAGE","url":"https://github.com/soketi/soketi"},{"type":"WEB","url":"https://github.com/soketi/soketi/releases/tag/1.6.0"}],"affected":[{"package":{"name":"@soketi/soketi","ecosystem":"npm","purl":"pkg:npm/%40soketi/soketi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-g6w6-h933-4rc5/GHSA-g6w6-h933-4rc5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}