Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-25893: vm2 sandbox may allow attacker to run code
CVE-2022-25893 · published 10 days ago
Summary
Versions of the vm2 package earlier than 3.9.10 can be tricked into executing any code the attacker wants, breaking the isolation it provides. This could let a malicious user gain access to the host system and take control of the sandbox environment. Upgrade vm2 to the latest version to restore safe isolation.
What to do
- Update GitHub Actions vm2 to version 3.9.10.
- Update vm2 to version 3.9.7-aikido.5.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.5.
- Update vm2 to version 3.9.7-aikido.6.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.6.
- Update vm2_project vm2 to version 3.9.10 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
< 3.9.10 Fix: upgrade to 3.9.10
|
| – | vm2_project | vm2 |
< 3.9.10 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
| Root:npm | – | vm2 |
< 3.9.7-aikido.5 < 3.9.7-aikido.6 Fix: upgrade to 3.9.7-aikido.5
|
| Root:npm | rootio | @rootio/vm2 |
< 3.9.7-root.io.5 < 3.9.7-root.io.6 Fix: upgrade to 3.9.7-root.io.5
|
Original advisory text
CVE-2022-25893 in vm2 - Patched by Root
Root has patched CVE-2022-25893 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25893
- https://github.com/advisories/GHSA-4w2j-2rg4-5mjw
- https://github.com/patriksimek/vm2/issues/444 Exploit Issue Tracking Third Party Advisory
- https://github.com/patriksimek/vm2/pull/445 Patch Third Party Advisory
- https://github.com/patriksimek/vm2/pull/445/commits/3a9876482be487b78a90ac459675... Patch Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-VM2-2990237 Exploit Patch Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-94Code Injection
CWE-471Modification of Assumed-Immutable Data (MAID)
Timeline
Published30 Sep 2026
Updated7 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta