Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40102
HistoryApr 11, 2023 - 2:50 a.m.

Arbitrary Code Execution

2023-04-1102:50:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
vm2
vulnerability
setup-sandbox.js
error.preparestacktrace
async errors
sandbox protections
code execution

EPSS

0.017

Percentile

87.9%

vm2 is vulnerable to Arbitrary Code Execution. The vulnerability exists because the newWrapped function of setup-sandbox.js does not properly handle host objects passed to Error.prepareStackTrace in case of unhandled async errors, which allows an attacker to bypass the sandbox protections and execution arbitrary code on the system.