SCA: security update for vm2 (GHSA-cchq-frgv-rjh5)

critical Tenable Self-Hosted Container Security Plugin ID 436588

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be
used for production. The maintenance of the project has been discontinued. In vm2 for versions up to
3.9.19, `Promise` handler sanitization can be bypassed with the `@@species` accessor property allowing
attackers to escape the sandbox and run arbitrary code, potentially allowing remote code execution inside
the context of vm2 sandbox. Version 3.10.0 contains a patch for the issue. (CVE-2023-37466)

See Also

https://github.com/advisories/GHSA-cchq-frgv-rjh5

Plugin Details

Severity: Critical

ID: 436588

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/6/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-37466

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/13/2023

Vulnerability Publication Date: 7/13/2023

Reference Information

CVE: CVE-2023-37466

cwe: CWE-94