Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2022-36067: vm2 sandbox lets attackers run code on host

CVE-2022-36067 · published 10 days ago
Summary

Versions of the vm2 sandbox library before 3.9.11 allow a user to break out of the isolated environment and execute commands on the server that runs it. This can let an attacker take control of the host system. Upgrade vm2 to version 3.9.11 or later as soon as possible; there are no other reliable work‑arounds.

What to do
  • Update GitHub Actions vm2 to version 3.9.11.
  • Update vm2 to version 3.9.7-aikido.2.
  • Update rootio @rootio/vm2 to version 3.9.7-root.io.2.
  • Update vm2 to version 3.9.7-aikido.5.
  • Update rootio @rootio/vm2 to version 3.9.7-root.io.5.
  • Update vm2 to version 3.9.7-aikido.6.
  • Update rootio @rootio/vm2 to version 3.9.7-root.io.6.
  • Update vm2_project vm2 to version 3.9.11 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions vm2 < 3.9.11
Fix: upgrade to 3.9.11
– vm2_project vm2 < 3.9.11
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Root:npm – vm2 < 3.9.7-aikido.2
< 3.9.7-aikido.5
< 3.9.7-aikido.6
Fix: upgrade to 3.9.7-aikido.2
Root:npm rootio @rootio/vm2 < 3.9.7-root.io.2
< 3.9.7-root.io.5
< 3.9.7-root.io.6
Fix: upgrade to 3.9.7-root.io.2
Original advisory text
CVE-2022-36067 in vm2 - Patched by Root
Root has patched CVE-2022-36067 in the vm2 package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
48% chance of attack within 30 days
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published30 Sep 2026
Updated30 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta