Impact
vm2 is a JavaScript sandbox library that isolates code execution. In versions 3.11.0 through 3.11.7 the sandbox fails to protect host TypedArray and ArrayBuffer prototypes from mutation. An attacker can use prototype-walking primitives to modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype. As a result, any typed array created by the host after VM.run() returns will expose attacker‑controlled properties, allowing the attacker to read, alter or execute code in the parent process. This effectively grants the attacker remote code execution within the hosting application.
Affected Systems
The affected vendor is patriksimek, product vm2. The vulnerable versions are 3.11.0 up to 3.11.7 inclusive. The fix was introduced in 3.11.8. All older versions are not affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers who can execute arbitrary code inside VM.run() can exploit the prototype pollution to escape the sandbox and modify host prototypes, giving them a foothold to read or alter sensitive data or to execute code in the host process. The likely attack vector is any untrusted JavaScript code that is evaluated with VM.run(), inferred from the description.
OpenCVE Enrichment
Github GHSA