In vm2 for versions up to 3.9.19, Promise handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code.
Red Hat Advanced Cluster Management for Kubernetes 2.7.7 already contains the fixes for this vulnerability, released at https://access.redhat.com/errata/RHSA-2023:4654