Логотип exploitDog
bind:CVE-2019-10761
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-10761

Количество 2

Количество 2

nvd логотип

CVE-2019-10761

больше 3 лет назад

This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-wf5x-cr3r-xr77

больше 3 лет назад

vm2 before 3.6.11 vulnerable to sandbox escape

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10761

This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.

CVSS3: 8.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wf5x-cr3r-xr77

vm2 before 3.6.11 vulnerable to sandbox escape

CVSS3: 8.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу