Impact
The vulnerability in vm2 between versions 3.9.6 and 3.11.6 permits a built‑in allowlist bypass that enables a sandbox escape. When the embedder explicitly allows the node:test built‑in, the internal lookup treats the scheme‑only key node:test as a generic host passthrough, providing a read‑only proxy to the host module. The proxy forwards calls to node:test.run(), which starts a separate Node process and accepts attacker‑controlled execArgv values, including the ability to supply arbitrary JavaScript via –eval. Executing this JavaScript in the host process yields full control over the system, compromising confidentiality, integrity, and availability.
Affected Systems
This issue affects the vm2 package from patriksimek, specifically versions 3.9.6 through 3.11.6. The exploit requires Node.js version 24 or newer, as those versions expose the node:test scheme‑only key in module.builtinModules.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. While an EPSS score is not available, the lack of a CISA KEV listing does not mitigate the risk, since the vulnerability is already exploitable via a simple require of node:test when enabled in the allowlist. Attackers can launch the exploit from within an application that uses vm2 and has node:test enabled, making exploitation straightforward in such contexts.
OpenCVE Enrichment
Github GHSA