Impact
vm2 before version 3.11.8 suffers from an incomplete fix to Error.cause sanitization, leaving sandbox‑escape capabilities when host‑wrapped AggregateError objects are caught during a single exception-handling traversal. Attackers can exploit a cycle‑detection bypass in the handleException routine to reach unsanitized host proxies stored in the error’s array, allowing them to execute arbitrary code within the sandbox and obtain sensitive process information. This flaw is a classic sandbox escape leading to full remote code execution, classified as CWE‑693.
Affected Systems
The only vendor explicitly identified is patriksimek providing the vm2 sandbox library. All versions prior to 3.11.8 are impacted. No other variants or vendor product lineages are listed.
Risk and Exploitability
The CVSS score of 9.5 indicates a high severity rating, and while the EPSS score is currently not available, the lack of a published mitigation elevates the exploitation risk. The flaw is not listed in the CISA KEV catalog, but the potential for complete remote code execution and process information disclosure means an attacker could gain full control of the host environment if the vulnerability is successfully leveraged. The likely attack vector involves malicious input into the vm2 sandbox that includes host‑wrapped AggregateError objects, a scenario that may arise from untrusted code execution or injection of crafted error structures. Given the high severity and clear path to control, the risk remains substantial.
OpenCVE Enrichment
Github GHSA