← Vulnerability feed

Vulnerability record · CVE-2023-30547 · published 17 April 2023

CVE-2023-30547: vm2 sandbox escape via unsanitized host exception handling

Vm2 Project · Vm2

vm2 versions up to 3.9.16 fail to sanitize host exceptions raised inside handleException(), letting untrusted sandboxed code reach host context. Because vm2 exists specifically to run untrusted code safely, a sandbox escape defeats its core security guarantee and can lead to arbitrary code execution on the host. It was patched in 3.9.17 with no known workarounds.

10.0 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-74 · Injection
10.0CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with scope change, public exploit references, and very high EPSS make this an urgent sandbox escape to patch.

What it is

vm2 versions up to 3.9.16 fail to sanitize host exceptions raised inside handleException(), letting untrusted sandboxed code reach host context. Because vm2 exists specifically to run untrusted code safely, a sandbox escape defeats its core security guarantee and can lead to arbitrary code execution on the host. It was patched in 3.9.17 with no known workarounds.

Impact

An attacker who can get code executed inside the sandbox gains arbitrary code execution in the host Node.js process, with the CVSS scope change indicating impact beyond the sandbox boundary.

Attack surface

Reached remotely over the network with no authentication or user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N), but only where an application passes attacker-controlled code into vm2.

Exploitation

Public exploit references are tagged in the advisory and a third-party gist, and EPSS is 0.72087 (99.4th percentile), indicating high predicted exploitation activity; it is not listed in CISA KEV.

What to do

  • Upgrade vm2 to version 3.9.17 or later, which contains the patch commits.
  • If upgrade is not immediately possible, remove or disable vm2 execution of untrusted code, since no workaround exists.
  • Audit applications and dependencies that pass user-supplied or third-party code into vm2 and treat them as exposed.
  • Monitor for new vm2 advisories, as this is one of several sandbox escapes in the project.

Detection

  • Search dependency manifests and lockfiles for vm2 versions below 3.9.17.
  • Alert on unexpected child_process, filesystem, or network activity originating from processes that host vm2.
  • Review application logs for untrusted code submissions that trigger host-level exceptions or errors.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-30547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-44005Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and…EPSS 0.83%10.0CVE-2026-44006Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary…EPSS 0.77%10.0CVE-2026-43997Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec…EPSS 0.77%10.0CVE-2026-26332Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.…EPSS 0.74%10.0CVE-2026-22709Vm2 project vm2 code injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio…EPSS 1.3%10.0CVE-2023-37903Vm2 project vm2 os command injection vulnerabilityvm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc…EPSS 4.2%10.0CVE-2023-37466Vm2 project vm2 code injection vulnerabilityvm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of th…EPSS 3.9%10.0CVE-2023-32314Vm2 project vm2 injection vulnerabilityvm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and includ…EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2023-30547), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.