FortiGuard
Fortinet’s Global Threat Intelligence and Research
Pwalia
Staff
Staff
Article Id 252212
Description vm2 is a sandbox solution that can run untrusted code with whitelisted Node's built-in modules. Exploiting the flaws, threat actors can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.
CVEs CVE-2022-36067CVE-2023-29017
Severity High
Last Revised Apr 12, 2023
Outbreak Report Link https://fortiguard.fortinet.com/outbreak-alert/vm2-sandbox-escape
Contributors