{"id":"GHSA-g6w6-h933-4rc5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g6w6-h933-4rc5","summary":"Soketi was exposed to Sandbox Escape vulnerability via vm2","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nAnyone who might have used Soketi with the `cluster` driver (or through PM2).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nGet the latest version of Soketi.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nNone. It's advised to upgrade to the latest version.\n\n### References\n_Are there any links users can visit to find out more?_\n- https://github.com/advisories/GHSA-cchq-frgv-rjh5\n- https://github.com/patriksimek/vm2/issues/533\n- https://github.com/Unitech/pm2/issues/5643\n","published":"2023-08-03T19:44:52Z","modified":"2023-08-03T19:44:52Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@soketi/soketi","fixedVersion":"1.6.0"}],"fix":{"url":"https://github.com/soketi/soketi/pull/927","label":"soketi/soketi#927"},"references":[{"type":"WEB","url":"https://github.com/soketi/soketi/security/advisories/GHSA-g6w6-h933-4rc5"},{"type":"WEB","url":"https://github.com/Unitech/pm2/issues/5643"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/issues/533"},{"type":"WEB","url":"https://github.com/soketi/soketi/pull/927"},{"type":"WEB","url":"https://github.com/soketi/soketi/commit/de12bff706c0d62e6a57dc1c7be3c4f014d0093a"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cchq-frgv-rjh5"},{"type":"PACKAGE","url":"https://github.com/soketi/soketi"},{"type":"WEB","url":"https://github.com/soketi/soketi/releases/tag/1.6.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-08-03T19:44:52Z"}}