#VU80135 Security features bypass in vm2 - CVE-2023-37466
Published: August 30, 2023 / Updated: October 25, 2024
vm2
Patrik Simek
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper validation of user-supplied input within the Promise handler. A remote attacker can pass specially crafted data to the application, bypass sanitization with `@@species` accessor property to escape the sandbox and run arbitrary code.