CVE-2023-29199Patch(vm2_project / vm2)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vm2_project vm2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
vm2

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-30: 1Patch / Workaround · 2026-01-30: 101-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    The post notes CVE-2026-22709 was fixed in vm2 3.10.2 and lists other sandbox‑escape CVEs, indicating a patch exists but no PoC or active exploitation is mentioned.

    10000133
    481 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more