Description
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.
Published: 2022-09-06
Score: 10 Critical
EPSS: 84.8% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mrgp-mrhc-5jrq vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host
History

Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 08 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
Redhat multicluster Engine
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.0::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat
Redhat acm
Redhat multicluster Engine

Mon, 19 Aug 2024 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.0::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat
Redhat acm
Redhat multicluster Engine

Subscriptions

Redhat Acm Multicluster Engine
Vm2 Project Vm2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-22T17:24:29.553Z

Reserved: 2022-07-15T00:00:00.000Z

Link: CVE-2022-36067

cve-icon Vulnrichment

Updated: 2024-08-03T09:51:59.996Z

cve-icon NVD

Status : Modified

Published: 2022-09-06T22:15:09.207

Modified: 2024-11-21T07:12:18.500

Link: CVE-2022-36067

cve-icon Redhat

Severity : Critical

Publid Date: 2022-09-07T00:00:00Z

Links: CVE-2022-36067 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses