CVE-2022-36067 is a critical sandbox escape vulnerability affecting vm2, a popular Node.js library used for running untrusted code. This flaw allows an attacker to bypass sandbox protections and achieve remote code execution on the host system. With a CVSS score of 10.0 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not currently on CISA's KEV catalog, exploit proof-of-concept code is publicly available, and the vulnerability has garnered significant community discussion and media attention, indicating a high likelihood of active exploitation. Organizations using vm2 versions prior to 3.9.11 are strongly advised to patch immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.11CPE matchmatch criteria | cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.