vm2 (Node.js sandbox)
Version check (in-sandbox)
const version = require("vm2/package.json").version;
console.log(version < "3.9.17" ? "vulnerable!" : "not vulnerable");CVE-2023-30547 / vm2 escape
{"code":"<base64-encoded JavaScript>"}# Exploit sends commands to the target; ensure the script uses the correct endpoint (e.g. /run)
python3 exploit.py http://TARGET/run
# Then at prompt: id, pwd, or reverse shell one-linerQuick reference
Item
Value
Last updated