
Critical vm2 Sandbox Bug Allows Attackers to Execute Code on Hosts
Security
📌 A critical vulnerability in the vm2 Node.js sandboxing library allows attackers to escape the sandbox and execute arbitrary code on the host system. The flaw, tracked as CVE-2024-37466 with a CVSS score of 9.8, affects vm2 versions prior to 3.9.19. Exploitation involves leveraging a prototype pollution issue to bypass sandbox protections and gain full control over the underlying host. The vulnerability was disclosed by security researcher SeungHyun Lee, who reported it to the vm2 maintainers. A patch was released in vm2 version 3.9.19 to address the issue, mitigating the risk of remote code execution.