{"id":"GHSA-xj72-wvfv-8985","summary":"vm2 Sandbox Escape vulnerability","details":"There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context.\n\n### Impact\nA threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.\n\n### Patches\nThis vulnerability was patched in the release of version `3.9.16` of `vm2`.\n\n### Workarounds\nNone.\n\n### References\nGithub Issue - https://github.com/patriksimek/vm2/issues/516\nPoC - https://gist.github.com/leesh3288/f05730165799bf56d70391f3d9ea187c\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [VM2](https://github.com/patriksimek/vm2)\n\nThanks to [Xion](https://twitter.com/0x10n) (SeungHyun Lee) of [KAIST Hacking Lab](https://kaist-hacking.github.io/) for disclosing this vulnerability.","aliases":["CVE-2023-29199"],"modified":"2023-11-08T04:12:17.211100Z","published":"2023-04-12T20:42:44Z","database_specific":{"cwe_ids":["CWE-913"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-04-12T20:42:44Z","nvd_published_at":"2023-04-14T19:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-xj72-wvfv-8985"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29199"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/issues/516"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/24c724daa7c09f003e556d7cd1c7a8381cb985d7"},{"type":"WEB","url":"https://gist.github.com/leesh3288/f05730165799bf56d70391f3d9ea187c"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/3.9.16"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.9.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-xj72-wvfv-8985/GHSA-xj72-wvfv-8985.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}