Impact
The vm2 library, versions 3.9.6 through 3.11.6, does not correctly enforce the restrictions defined by vm.freeze() and vm.readonly(). When a sandboxed script interrogates the property descriptor of a frozen object, the accessor descriptor can be retrieved even if the object is marked read‑only. The attacker can then invoke the underlying host setter to modify the property.
Affected Systems
The issue affects the patriksimek vm2 package, a Node.js sandboxing utility. Any application that imports vm2 within the affected version range can expose host objects to sandboxed code; the vulnerability applies to all released builds between 3.9.6 and 3.11.6 inclusive, and the fix is implemented in 3.11.7.
Risk and Exploitability
With a CVSS score of 6.3, the vulnerability has moderate severity. There is no EPSS data, and the vulnerability is not listed in KEV, suggesting limited exploitation awareness. Exploitation requires the attacker to control or influence code that is executed in the vm2 sandbox, using JavaScript functions like Object.getOwnPropertyDescriptor or __lookupSetter__ to retrieve the host setter and modify a frozen property. Because of these prerequisites, the attack is likely limited to scenarios where the sandboxed code is granted access to host objects.
OpenCVE Enrichment
Github GHSA