CVE-2023-29199
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 25.12%
- CWE
- CWE-913
- Published
- 2023-04-14
- Last modified
- 2026-03-13
Affected products
- patriksimek vm2
Weakness type
Related vulnerabilities
- CVE-2025-68613 — n8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2022-36067 — vm2 vulnerable to Sandbox Escape before v3.9.11
- CVE-2023-29017 — vm2 Sandbox Escape vulnerability
- CVE-2023-50386 — Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-25270 — Remote Code Execution via Unauthenticated Configuration Manipulation
- CVE-2023-4041 — Second Stage Gecko Bootloader GBL Parser Buffer Overrun Vulnerability