CVE-2023-29017 is a critical sandbox escape vulnerability affecting vm2, a popular Node.js sandbox library, in versions prior to 3.9.15. This flaw allows an attacker to bypass sandbox protections and achieve remote code execution on the host system. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk due to its network-based attack vector and low attack complexity. While not yet in CISA's KEV catalog, exploit Proof-of-Concepts are publicly available, and it has garnered substantial community discussion and media attention, including multiple articles from BleepingComputer. Organizations using vm2 should prioritize updating to version 3.9.15 immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.15CPE matchmatch criteria | cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.