{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avyperlangvyper/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*","cpe:2.3:a:vyperlang:vyper:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-30547"},{"cvss":9.8,"id":"CVE-2023-32314"},{"cvss":3.7,"id":"CVE-2023-32675"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (\u003c= 3.9.16)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","sandbox-escape","code-execution"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe JavaScript library vm2, widely used for running untrusted code in a sandboxed environment, contains multiple critical vulnerabilities that permit attackers to break out of the sandbox. These vulnerabilities, tracked under CVE-2023-30547, CVE-2023-32314, and CVE-2023-32675, stem from improper sanitization of error objects and mishandling of asynchronous operations. By exploiting these flaws, an attacker can bypass the security boundaries intended to isolate the guest code, leading to arbitrary code execution on the underlying host operating system. Given the library's role in security-sensitive isolation tasks, this risk is severe for any application or platform that processes user-supplied JavaScript using vulnerable versions of the vm2 sandbox. Defenders should prioritize auditing dependencies and migrating to alternative isolation mechanisms, as vm2 has been deprecated due to persistent sandbox escape issues.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a guest user to elevate privileges from the sandbox to the host environment. This can lead to full system compromise, data exfiltration, or lateral movement within the network. These flaws impact a wide range of Node.js applications that utilize vm2 for security-critical sandboxing of user-provided content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eIdentify all applications within the environment that utilize the vm2 library via software composition analysis tools. Since the library is deprecated and no longer receives security updates, migration to a more secure isolation alternative such as Web Workers or dedicated virtual machines is required. Review all instances of code executing user-supplied JavaScript to ensure the sandbox is removed or replaced.\u003c/p\u003e\n","date_modified":"2026-09-04T18:06:45Z","date_published":"2026-09-04T18:06:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/","summary":"Multiple vulnerabilities in the vm2 JavaScript sandbox library, including CVE-2023-30547, CVE-2023-32314, and CVE-2023-32675, allow attackers to escape the sandbox and execute arbitrary code on the host system.","title":"Multiple Arbitrary Code Execution Vulnerabilities in vm2","url":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vyperlang:vyper:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}