Skip to content

Instantly share code, notes, and snippets.

View agathoz's full-sized avatar
馃拃
PEGGING

獗疓ATH脴Z agathoz

馃拃
PEGGING
View GitHub Profile

Sandbox Escape in [email protected]

Summary

There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside handleException() which can be used to escape the sandbox and run arbitrary code in host context.

Proof of Concept