CVE-2022-36067
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 85.41%
- CWE
- CWE-913
- Published
- 2022-09-06
- Last modified
- 2026-03-13
Affected products
- patriksimek vm2
Weakness type
Related vulnerabilities
- CVE-2025-68613 — n8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2023-29017 — vm2 Sandbox Escape vulnerability
- CVE-2023-50386 — Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
- CVE-2023-29199 — vm2 Sandbox escape vulnerability
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-25270 — Remote Code Execution via Unauthenticated Configuration Manipulation
- CVE-2023-4041 — Second Stage Gecko Bootloader GBL Parser Buffer Overrun Vulnerability