CVE-2023-29017Active Exploitation(vm2_project / vm2)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-07)
  • 6 total mentions across 4 days

Affected systems

Products
vm2

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 3PoC Mentioned / Linked · 2026-01-28: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-05-06: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 201-2801-3005-0605-07
Signal classification4 categories
Active Exploitation
233.3%
Patch
233.3%
Disclosure
116.7%
General
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-01-301
Patch1
2026-05-061
Active Exploitation1
2026-05-073
Disclosure1General1Patch1
Full discourse6 posts
  • Glitch News@glitch4techs
    Disclosure

    🚨 تحذير أمني عاجل لمطوري Node.js! اكتشاف ثغرة Sandbox Escape في مكتبة vm2 الشهيرة (CVE-2023-29017) تسمح للمهاجمين بالسيطرة الكاملة على الخادم المضيف. 🛠 التحليل التقني: - النوع: تنفيذ أوامر عن بُعد (RCE). - الخطورة: 10/10 (حرجة جداً). - الآلية: استغلال ثغرات في معالجة الكائنات لتجاوز حدود العزل البرمجي. 🎯 لماذا هذا مهم؟ إذا كان تطبيقك يسمح بتشغيل نصوص برمجية من المستخدمين (مثل أدوات الأتمتة أو المحررات البرمجية) ويستخدم vm2، فأنت عرضة للاختراق الفوري. ⚠️ التوصية: مكتبة vm2 أصبحت الآن 'End of Life'. يُنصح بالانتقال فوراً إلى البدائل مثل isolated-vm أو استخدام الحاويات (Containers) لضمان الأمان. التفاصيل الكاملة في مقالنا الجديد على Glitch4Techs 👇 #أمن_المعلومات #برمجة #NodeJS #CyberSecurity #Glitch4Techs 🔗 اقرأ المقال كاملاً عبر موقعنا:

    Post summary

    The post announces a critical RCE in the vm2 Node.js library (CVE‑2023‑29017), warns about immediate risk, and advises moving to alternatives.

    1000092
    23 followersView on X
  • Glitch News@glitch4techs
    Patch

    🚨 تحذير أمني عاجل لمطوري Node.js! اكتشاف ثغرة Sandbox Escape في مكتبة vm2 الشهيرة (CVE-2023-29017) تسمح للمهاجمين بالسيطرة الكاملة على الخادم المضيف. 🛠 التحليل التقني: - النوع: تنفيذ أوامر عن بُعد (RCE). - الخطورة: 10/10 (حرجة جداً). - الآلية: استغلال ثغرات في معالجة الكائنات لتجاوز حدود العزل البرمجي. 🎯 لماذا هذا مهم؟ إذا كان تطبيقك يسمح بتشغيل نصوص برمجية من المستخدمين (مثل أدوات الأتمتة أو المحررات البرمجية) ويستخدم vm2، فأنت عرضة للاختراق الفوري. ⚠️ التوصية: مكتبة vm2 أصبحت الآن 'End of Life'. يُنصح بالانتقال فوراً إلى البدائل مثل isolated-vm أو استخدام الحاويات (Containers) لضمان الأمان. التفاصيل الكاملة في مقالنا الجديد على Glitch4Techs 👇 #أمن_المعلومات #برمجة #NodeJS #CyberSecurity #Glitch4Techs 🔗 اقرأ المقال كاملاً عبر موقعنا:

    Post summary

    The post discloses a critical CVE‑2023‑29017 RCE in vm2 with detailed technical info and urges developers to drop the library and migrate to alternatives or containers.

    1000074
    23 followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    CVE‑2026‑22709 is fixed in vm2 v3.10.2, and the library has suffered a series of sandbox escape vulnerabilities over recent years.

    10000133
    481 followersView on X
  • DailyCVE@dailycve
    General

    🔴 vm2, Sandbox Escape, #CVE-2023-29017 (Critical) https://dailycve.com/vm2-sandbox-escape-cve-2023-29017-critical/

    Post summary

    The post merely announces a critical sandbox escape vulnerability (CVE‑2023‑29017) for vm2, without offering any PoC, exploit, or mitigation information.

    0000054
    196 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    vm2 3.10.4 processed untrusted JavaScript on thousands of servers last week. This Node.js sandbox library pulls 1.3M+ weekly npm downloads. It's embedded in online coding platforms, automation pipelines, and SaaS apps designed to isolate code execution. CVE-2026-26956 was disclosed on May 6, 2026. It affects versions 3.10.4 and earlier. The fix landed in 3.10.5, with the latest release at 3.11.2. The vulnerability triggers on Node.js 25 when WebAssembly exception handling and JSTag are enabled - confirmed on v25.6.1. An attacker crafts a TypeError through Symbol-to-string conversion. This generates a host-side error object that leaks into the sandbox without sanitization. The error's constructor chain exposes Node.js internals, including the process object. From there, the attacker accesses require and child_process modules to execute arbitrary commands on the host. This marks the fourth critical sandbox escape in vm2: CVE-2026-22709 in January 2026, plus CVE-2023-30547, CVE-2023-29017, and CVE-2022-36067. vm2 maintainers have stated the library is no longer viable as a true sandbox. They recommend isolated-vm or Node's built-in permission model instead. A tool built for containment becomes the path to host compromise.

    Post summary

    CVE-2026-26956 facilitated sandbox escape in vm2, compromising thousands of servers last week. A remediation patch is available in version 3.10.5.

    0000048
    102 followersView on X
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2023-29017 : CRITICAL SANDBOX BYPASS RCE ALERT 🚨 NodeJS A sandbox escape vulnerability has been disclosed in the vm2 Node.js library — a security-critical component used to execute untrusted JavaScript code in isolated environments. Risk Severity: Critical (CVSS 9.8+, active exploitation, public PoCs, internet-facing abuse observed) Impact: Arbitrary remote code execution on the host server Complete sandbox bypass Full compromise of Node.js applications Theft of secrets, credentials, and environment variables Persistent backdoors, ransomware, crypto-miners Lateral movement to connected services Root Cause: CWE-254 (Improper Security Control / Sandbox Escape) vm2 fails to properly isolate Error.prepareStackTrace during unhandled asynchronous errors, allowing sandboxed code to access host objects, pollute prototypes, and escape into the host execution context. Attackers can: Submit malicious JavaScript to any vm2-backed execution endpoint Trigger unhandled async errors (Promise rejection / async throw) Abuse error stack handling to access host globals Execute arbitrary JavaScript and OS commands Fully compromise the underlying Node.js process Are You Affected? Vulnerable: vm2 < 3.9.15 Scope: Any application executing user-supplied JavaScript via vm2 Online REPLs & code playgrounds Serverless / function platforms CMS scripting engines Data pipelines with custom JS logic Chatbots or APIs evaluating JavaScript Immediate Action Required: Update: Upgrade to vm2 3.9.15+ immediately Mitigation: Disable vm2 execution until patched if upgrade is delayed Audit: Hunt for unhandledRejection events in vm2 contexts Monitor Node.js processes for unexpected child_process, fs, or outbound traffic Investigate attempts to access Error.prepareStackTrace, Function, process, or prototype manipulation vm2’s core security boundary is broken. Any exposed instance should be treated as an active RCE target. Patch without delay. 🛡️ #nodejs #security #ostorlabCVE

    Post summary

    Critical sandbox escape RCE in vm2 is being actively exploited; immediate patch to 3.9.15+ is required.

    00000154
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more