CVE-2021-23555

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/02/2022
Last modified:
22/02/2022

Description

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* 3.9.6 (excluding)