CVE-2023-37903Disclosure(vm2_project / vm2)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vm2_project vm2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-01-30); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
vm2

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-01-30: 2Mentions · 2026-05-07: 1Mentions · 2026-05-30: 2Mentions · 2026-06-13: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-01-30: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-30: 2Technical Details · 2026-06-13: 101-3005-0705-3006-13
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1Patch1
2026-05-071
Disclosure1
2026-05-302
Disclosure1Patch1
2026-06-131
Patch1
Full discourse6 posts
  • TheTechWorldPodcast@TheTechWorldPod
    Disclosure

    The discovery of CVE-2023-37903 in July 2023 also led Simek to announce that the project was being discontinued. However, these references have since been removed from the latest README file available on its GitHub repository after the project was resurrected late last year. The Security page has also been updated as of October 2025 to mention that vm2 3.x versions are being actively maintained.

    Post summary

    Vulnerability CVE‑2023‑37903 was discovered in July 2023, prompting the project's discontinuation. It was later revived and its security page updated to note active maintenance of vm2 3.x versions.

    10000105
    481 followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    The text states that CVE-2026-22709, a sandbox escape in vm2, is fixed in version 3.10.2 and lists several related sandbox‑escape CVEs.

    10000133
    481 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default require: requireOpts = false assigns requireOpts = false, producing the exact configuration the patch was designed to prevent. This issue has been patched in version 3.11.4.

    Post summary

    CVE-2023-37903 in vm2 Node.js sandbox is disclosed with detailed bypass mechanics, and the flaw is patched in version 3.11.4.

    0000024
    44 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    GHSA-m4wx-m65x-ghrr: vm2 sandbox escape, CVSS 10. A previous fix for CVE-2023-37903 was bypassed via a strict equality check flaw in nodevm.js. Network-exploitable, no auth needed, full RCE scope. Update vm2 now. https://secalerts.co/vulnerability/GHSA-m4wx-m65x-ghrr https://t.co/I1FS3LI8iK

    Post summary

    The tweet announces a severe network‑exploitable sandbox escape in vm2, detailing the technical flaw and urging users to update the library.

    0000092
    826 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVSS 10.0 in vm2 (npm). CVE-2026-47137 is a sandbox escape that bypasses the fix for CVE-2023-37903 - unauthenticated, no interaction needed, full compromise possible. If vm2 is in your stack, treat this as critical. #nodejs #security https://secalerts.co/vulnerability/CVE-2026-47137 https://t.co/y3riLEpaSZ

    Post summary

    The tweet announces a new Critical CVE‑2026‑47137 sandbox escape in vm2 (npm), noting it bypasses a prior fix, is unauthenticated with no interaction needed, and carries a CVSS 10.0 score, urging users to treat it as critical.

    0000091
    826 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 vm2 (Nodejs sandbox), Sandbox Escape via Custom Inspect + WASM, #CVE-2023-37903 (Critical) https://dailycve.com/vm2-nodejs-sandbox-sandbox-escape-via-custom-inspect-wasm-cve-2023-37903-critical/

    Post summary

    The tweet announces a critical sandbox escape vulnerability in vm2 (Node.js) identified as CVE-2023-37903, describing how the exploit leverages custom Inspect and WebAssembly.

    0000048
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more