{"id":"GHSA-whpj-8f3w-67p5","summary":"vm2 Sandbox Escape vulnerability","details":"A sandbox escape vulnerability exists in vm2 for versions up to 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`.\n\n### Impact\nA threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.\n\n### Patches\nThis vulnerability was patched in the release of version `3.9.18` of `vm2`.\n\n### Workarounds\nNone.\n\n### References\nPoC - https://gist.github.com/arkark/e9f5cf5782dec8321095be3e52acf5ac\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [VM2](https://github.com/patriksimek/vm2)\n\nThanks to @arkark (Takeshi Kaneko) of GMO Cybersecurity by Ierae, Inc. for disclosing this vulnerability.","aliases":["CVE-2023-32314"],"modified":"2026-03-11T07:48:29.194358Z","published":"2023-05-15T20:50:51Z","database_specific":{"github_reviewed_at":"2023-05-15T20:50:51Z","nvd_published_at":"2023-05-15T20:15:09Z","cwe_ids":["CWE-74"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32314"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/d88105f99752305c5b8a77b63ddee3ec86912daf"},{"type":"WEB","url":"https://gist.github.com/arkark/e9f5cf5782dec8321095be3e52acf5ac"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/3.9.18"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.9.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-whpj-8f3w-67p5/GHSA-whpj-8f3w-67p5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}