Lucene search

K
osvGoogleOSV:GHSA-6PW2-5HJV-9PF7
HistoryFeb 12, 2022 - 12:00 a.m.

Sandbox bypass in vm2

2022-02-1200:00:38
Google
osv.dev
16
vm2
software
sandbox bypass
vulnerability
host machine
arbitrary code

EPSS

0.002

Percentile

61.9%

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

EPSS

0.002

Percentile

61.9%