High severity8.3NVD Advisory· Published Jul 13, 2022· Updated Jun 17, 2026
CVE-2019-10761
CVE-2019-10761
Description
This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
vm2npm | < 3.6.11 | 3.6.11 |
Affected products
3cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*range: <3.6.11
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
7- github.com/patriksimek/vm2/commit/4b22d704e4794af63a5a2d633385fd20948f6f90nvdPatchThird Party AdvisoryWEB
- github.com/patriksimek/vm2/issues/197nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wf5x-cr3r-xr77ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10761ghsaADVISORY
- snyk.io/vuln/SNYK-JS-VM2-473188nvdThird Party AdvisoryWEB
- gist.github.com/JLLeitschuh/609bb2efaff22ed84fe182cf574c023aghsaWEB
- github.com/patriksimek/vm2/issues/197ghsaWEB
News mentions
0No linked articles in our index yet.