Impact
The vulnerability is present in vm2 versions 3.11.3 through 3.11.6 and allows code running in a NodeVM to gain host process privileges. Node.js's host node:sqlite module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable. The module resolver interprets any request beginning with 'node:' as a core‑module request and only strips a single 'node:' prefix. A sandboxed script can therefore request 'node:node:sqlite', causing the resolver to load the node:sqlite entry again. Untrusted code can create a DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library packaged with the untrusted plugin. SQLite loads the library into the Node.js host process and invokes its native entry point, granting the sandboxed code arbitrary native code execution with the host process's privileges.
Affected Systems
The affected product is patriksimek:vm2, specifically all releases from 3.11.3 up to and including 3.11.6. Any Node.js application that incorporates vm2 with builtin modules enabled, particularly node:sqlite, is vulnerable. No other vendors or products are mentioned.
Risk and Exploitability
The CVSS score of 9.4 categorizes this issue as Critical, and while an EPSS score is not available, the exploitation requires only that the offending plugin code be executed within the VM. The vulnerability is not yet listed in the CISA KEV catalog, but the high severity and the ability to load arbitrary native code suggest that exploitation could be straightforward in environments that allow plugin extensions. The likely attack vector is the inclusion of a malicious plugin or a vulnerable third‑party package that enables node:sqlite and database extension loading within the sandbox.
OpenCVE Enrichment
Github GHSA