| Description | vm2 is a sandbox solution that can run untrusted code with whitelisted Node's built-in modules. Exploiting the flaws, threat actors can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. |
| CVEs | CVE-2022-36067, CVE-2023-29017 |
| Severity | High |
| Last Revised | Apr 12, 2023 |
| Outbreak Report Link | https://fortiguard.fortinet.com/outbreak-alert/vm2-sandbox-escape |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.