Impact
vm2 implements a sandbox for executing untrusted JavaScript. In versions 3.10.0 through 3.11.7, Promises returned from the host realm into the sandbox are not flagged as handled when they cross the bridge boundary. Only Promises created inside the sandbox receive a rejection‑swallowing wrapper, and the bridge installs host‑side rejection sanitizers only when sandbox code calls .then, .catch, or .finally. Consequently, sandbox code that calls a host function returning a rejected Promise and simply ignores the returned value leaves an unhandled rejection in the host process. Node.js’s default unhandled‑rejection policy terminates the process, resulting in a denial‑of‑service. The flaw can be triggered by any sandboxed code that invokes a host API such as events.once exposed via the NodeVM events builtin, or other embedder‑provided Promise‑returning APIs.
Affected Systems
The vulnerability affects the patriksimek:vm2 sandbox library for Node.js. All releases from version 3.10.0 up to and including 3.11.7 are impacted. The issue was fixed in version 3.11.8 and later.
Risk and Exploitability
The CVSS base score of 9.2 indicates high severity. Exploitation requires running untrusted JavaScript that calls a host function returning a rejected Promise without handling the rejection. While no publicly known exploits are listed in the CISA KEV catalog, the lack of mitigation in vulnerable releases means that any such sandboxed code can terminate the hosting Node.js process. The EPSS score is not available, so the probability of exploitation cannot be quantified, but the worst‑case impact is a critical application shutdown.
OpenCVE Enrichment
Github GHSA