HIGH 7.6 npm
Directus affected by VM2 sandbox escape vulnerability
GHSA-22rr-f3p8-5gf8
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
In vm2 for versions up to 3.9.19, Promise handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code. Within Directus this applies to the "Run Script" operation in flows being able to escape the sandbox running code in the main nodejs context.
Patches
Patched in v10.6.0 by replacing vm2 with isolated-vm
Workarounds
None
References
https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5
References
- WEB https://github.com/directus/directus/security/advisories/GHSA-22rr-f3p8-5gf8
- WEB https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5
- WEB https://github.com/directus/directus/pull/19332
- WEB https://github.com/directus/directus/commit/284156426fa94f688e8d65a7a4f34f9e6705f058
- PACKAGE https://github.com/directus/directus
Ready to move
Start Securing
Free, no credit card | First findings in minutes