Impact
In vulnerable versions of the vm2 sandbox, the NodeVM constructor evaluates the require option with a type guard that accepts an array shaped value. Providing a require value such as [] when nesting is enabled allows the resolver to be constructed with only a nesting override, giving the attacker the host vm2 module. The attacker can then create an inner NodeVM with a custom allowlist that may include powerful built‑ins like child_process, and execute arbitrary host commands, escaping the intended sandbox entirely.
Affected Systems
The vulnerability affects the npm package vm2 from patriksimek. Versions 3.11.4 through 3.11.6 inclusive are vulnerable when a NodeVM is instantiated with nesting: true and a require value shaped as an array. Later releases, starting with 3.11.7, contain the fix.
Risk and Exploitability
The flaw carries a CVSS score of 9.5, indicating critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only the ability to execute JavaScript within a NodeVM that has nesting enabled, a common scenario when running untrusted code. Once triggered, the attacker gains full control over the host Node.js process.
OpenCVE Enrichment
Github GHSA