CVE-2021-23555: Sandbox Bypass
A flaw was found in vm2, where the sandbox can be bypassed via direct access to host error objects generated by node internals during the generation of stack traces. This flaw allows an attacker to execute arbitrary code on the host machine.
Other sources
The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23555?
CVE-2021-23555 is considered critical due to its potential to allow arbitrary code execution on the host machine.
How do I fix CVE-2021-23555?
To fix CVE-2021-23555, update vm2 to version 3.9.6 or later.
What systems are affected by CVE-2021-23555?
CVE-2021-23555 affects all versions of the vm2 package prior to 3.9.6.
Can CVE-2021-23555 lead to data exposure?
Yes, CVE-2021-23555 can potentially lead to data exposure by allowing unauthorized access to host resources.
Is there a workaround for CVE-2021-23555?
There are no specific workarounds for CVE-2021-23555; upgrading to the patched version is recommended.