All CVEs — page 179 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows code running inside the sandbox to overwrite the `Symbol.species` property of a host Promise, leading to arbitrary code execution on the host. It matters because it bypasses security measures intended to prevent such attacks.
This vulnerability allows attackers to escape the sandbox and execute arbitrary commands on the host system by exploiting the DANGEROUS_BUILTINS denylist in vm2 NodeVM versions before 3.12.1.
The flaw allows untrusted code to escape a sandbox and execute arbitrary code on the host system by calling non-strict functions with an undefined receiver, leading to Remote Code Execution (RCE).