Impact
A sandbox escape flaw in vm2 allows an attacker to execute arbitrary code in the host Node.js process. The vulnerability arises when a host Promise that contains a rejected error with non‑primitive properties is routed through a proxy indirection (e.g., Function.prototype.call or .apply). The sanitization logic misidentifies the target as a host call, permitting the raw host error—including attached host objects such as process—to leak into untrusted sandbox code. The attacker can then use these objects to invoke child process execution or other privileged operations. This flaw is classified under CWE-94, code injection and runtime code execution.
Affected Systems
The affected product is vm2 v3.11.6, maintained by patriksimek. The issue exists only in that specific release; support exists in later versions, with v3.11.7 and beyond incorporating the fix.
Risk and Exploitability
The CVSS score is 10, indicating a critical severity. EPSS data is not available, leaving the exploit probability uncertain, and the vulnerability is not yet listed in CISA KEV. The likely attack vector requires the embedder to expose a host‑realm Promise to the sandbox, typically through the sandbox option or an external module’s async method. If this condition is met, the exploit is straightforward: trigger a rejected Promise with an Error that carries a host object reference, then the sandbox code obtains a proxy to that host object and invokes methods such as require('child_process').execSync, achieving remote code execution with host privileges.
OpenCVE Enrichment
Github GHSA