Back to overview

CVE-2022-36067

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

Metadata

CVE ID
CVE-2022-36067
State
PUBLISHED
Assigner
GitHub_M
Reserved
2022-07-15 00:00 UTC
Published
2022-09-06 00:00 UTC
Last updated
2025-04-22 17:24 UTC
Primary CWE
CWE-913
CWE-913: Improper Control of Dynamically-Managed Code Resour…
Vendor / Product
patriksimek / vm2
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
patriksimek vm2 < 3.9.11
Weakness (CWE)
CWESourceDescription
CWE-913 cna CWE-913: Improper Control of Dynamically-Managed Code Resources
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview