CVE-2023-29017
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 76.98%
- CWE
- CWE-913
- Published
- 2023-04-06
- Last modified
- 2026-03-13
Affected products
- patriksimek vm2
Weakness type
Related vulnerabilities
- CVE-2025-68613 — n8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2022-36067 — vm2 vulnerable to Sandbox Escape before v3.9.11
- CVE-2023-50386 — Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
- CVE-2023-29199 — vm2 Sandbox escape vulnerability
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-25270 — Remote Code Execution via Unauthenticated Configuration Manipulation
- CVE-2023-4041 — Second Stage Gecko Bootloader GBL Parser Buffer Overrun Vulnerability