{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3osamsungexynos_auto_t5123_firmware-/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ethyca:fides:*:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_9820_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_980_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_850_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_1080_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_2100_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_modem_5123_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_modem_5300_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:samsung:exynos_auto_t5123_firmware:-:*:*:*:*:*:*:*","cpe:2.3:a:opswat:metadefender_kiosk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":2.7,"id":"CVE-2023-37480"},{"cvss":5.3,"id":"CVE-2023-37367"},{"cvss":9.8,"id":"CVE-2023-36657"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2"],"_cs_severities":["critical"],"_cs_tags":["sandbox-escape","nodejs","code-execution","cve-2026-47686"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe vm2 sandbox library is subject to multiple critical vulnerabilities, tracked as CVE-2023-37480, CVE-2023-37367, and CVE-2023-36657. These vulnerabilities arise from flaws within the sandbox implementation that permit an attacker to escape the restricted environment. By bypassing the sandbox constraints, an unauthenticated attacker can execute arbitrary code on the host system, manipulate sensitive data, perform denial of service attacks, or disclose confidential information. Because vm2 is frequently used to execute untrusted JavaScript code in server-side environments, these vulnerabilities pose a significant risk to applications relying on this library for process isolation. Defenders should verify if their internal applications or third-party dependencies utilize vulnerable versions of vm2 and prioritize upgrading to secure versions or migrating to alternative sandboxing solutions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities leads to full sandbox escape, granting the attacker the ability to execute code with the privileges of the Node.js process. This may result in total system compromise, exfiltration of application secrets, and disruption of critical business services through denial of service. The scope of impact is widespread across any server-side application using the affected library versions for code evaluation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all applications within the environment utilizing the vm2 library via software composition analysis (SCA) or dependency auditing tools.\u003c/li\u003e\n\u003cli\u003ePatch or update affected applications to the latest secure version of vm2 immediately.\u003c/li\u003e\n\u003cli\u003eIn environments where patching is not immediately feasible, evaluate the implementation of secondary security controls such as containerization or restricted service accounts to limit the blast radius of a potential sandbox escape.\u003c/li\u003e\n\u003cli\u003eReview application logs for unusual patterns or child process spawning initiated by the Node.js runtime environment associated with the vm2 library.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T18:45:50Z","date_published":"2026-08-17T18:42:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-vm2-vulnerabilities/","summary":"The vm2 sandbox library is affected by multiple critical vulnerabilities, including remote code execution via sandbox escape, which allow attackers to manipulate data, disclose information, or execute arbitrary code.","title":"Multiple Vulnerabilities in vm2 Sandbox Library","url":"https://feed.craftedsignal.io/briefs/2026-08-vm2-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:samsung:exynos_auto_t5123_firmware:-:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}