Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2023-32314: vm2 sandbox escape can run code on host
CVE-2023-32314 · published 11 days ago
Summary
Versions of the vm2 sandbox up to 3.9.17 let a malicious script break out of its isolation and execute commands on the server that runs it. This gives an attacker the ability to take control of the host system. Upgrade vm2 to version 3.9.18 as soon as possible; there is no other fix available.
What to do
- Update GitHub Actions vm2 to version 3.9.18.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.7.
- Update vm2 to version 3.9.17-aikido.10.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.10.
- Update GitHub Actions vm2 to version 3.9.17-aikido.9.
- Update rootio @rootio/vm2 to version 3.9.17-root.io.9.
- Update GitHub Actions vm2 to version 3.9.17-aikido.7.
- Update vm2 to version 3.9.7-aikido.5.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.5.
- Update vm2 to version 3.9.7-aikido.6.
- Update rootio @rootio/vm2 to version 3.9.7-root.io.6.
- Update vm2_project vm2 to version 3.9.18 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | vm2 |
< 3.9.18 Fix: upgrade to 3.9.18
|
| – | vm2_project | vm2 |
< 3.9.18 cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* |
| Root:npm | rootio | @rootio/vm2 |
< 3.9.17-root.io.7 < 3.9.17-root.io.10 < 3.9.17-root.io.9 < 3.9.7-root.io.5 < 3.9.7-root.io.6 Fix: upgrade to 3.9.17-root.io.7
|
| Root:npm | – | vm2 |
< 3.9.17-aikido.10 < 3.9.7-aikido.5 < 3.9.7-aikido.6 Fix: upgrade to 3.9.17-aikido.10
|
| Root:npm | GitHub Actions | vm2 |
< 3.9.17-aikido.9 < 3.9.17-aikido.7 Fix: upgrade to 3.9.17-aikido.9
|
Original advisory text
CVE-2023-32314 in vm2 - Patched by Root
Root has patched CVE-2023-32314 in the vm2 package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-32314
- https://github.com/advisories/GHSA-whpj-8f3w-67p5
- https://gist.github.com/arkark/e9f5cf5782dec8321095be3e52acf5ac Exploit Third Party Advisory
- https://github.com/patriksimek/vm2/commit/d88105f99752305c5b8a77b63ddee3ec86912d... Patch
- https://github.com/patriksimek/vm2/releases/tag/3.9.18 Release Notes
- https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
10.0
Critical
Type
CWE-74Injection
Timeline
Published30 Sep 2026
Updated30 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta