Impact
A remote code execution flaw exists in VM2 before version 3.11.7. When the sandbox option require.external is enabled without a dedicated require.root that excludes the node_modules directory, code running inside the sandbox can load VM2’s own package. The attacker can then create an unrestricted NodeVM instance and invoke child_process to run arbitrary host operating system commands. This weakness directly grants the attacker full control over the environment in which the sandbox is executed.
Affected Systems
The affected product is VM2, packaged by patriksimek. All releases under version 3.11.7 are vulnerable; no other supported versions are listed.
Risk and Exploitability
The CVSS score of 10 classifies this as critical. The EPSS score is listed as not available, yet the lack of a specific exploitation probability does not diminish the potential impact. The vulnerability is not included in the CISA KEV catalog. Attackers can trigger the flaw by delivering crafted sandbox code that uses require.external to import VM2 packages, leading to unrestricted child_process execution. The risk remains high; immediate remediation is recommended.
OpenCVE Enrichment
Github GHSA