Impact
vm2 versions prior to 3.11.7 contain a sandbox escape flaw that allows an attacker who can execute the vm2 CLI to run arbitrary code in the host Node.js process. The vulnerability is triggered by supplying a malicious script file that calls require(__filename), causing the script to re‑execute itself outside the sandbox and access host modules such as fs and child_process. The effect is full control over the host process, enabling file manipulation, arbitrary commands, and potentially complete system compromise. This vulnerability is identified as CWE‑453. The description makes clear that the impact is code execution, with the potential to read, modify, and execute files on the machine running the process.
Affected Systems
The affected product is vm2, a sandboxing framework delivered by patriksimek. Versions earlier than 3.11.7 are impacted. Any deployment of vm2 that relies on the CLI interface and may receive malicious script input is vulnerable.
Risk and Exploitability
The CVSS base score of 9.3 indicates critical severity. Because the flaw requires the attacker to run the vm2 CLI, the vector is inferred to be local or command‑line execution; remote exploitation would necessitate another vulnerability to gain CLI access. The EPSS score is not available, but the absence of a record in the CISA KEV catalog suggests no widespread public exploitation has been reported yet. Nonetheless, the high severity and the ability to escape the sandbox make this a risk worth addressing promptly.
OpenCVE Enrichment
Github GHSA