Impact
The vulnerability is a sandbox escape in NodeVM that allows code running inside the sandbox to access host prototypes via console._stdout and console._stderr. By overwriting EventEmitter.prototype.emit, an attacker can trigger process events and execute arbitrary code within the process context, bypassing code generation restrictions. The weakness an access control flaw and is categorized as CWE-913.
Affected Systems
The affected product is VM2 provided by patriksimek. All releases before version 3.11.8 are vulnerable, regardless of Node.js version. Vendors or developers using these earlier VM2 releases need to upgrade.
Risk and Exploitability
The CVSS score of 10 indicates extreme severity. While an EPSS value is not available, the lack of listing in the CISA KEV catalog does not diminish the risk; the flaw allows an attacker who can inject code into the sandbox to run code with full process privileges. The most probable attack vector is local: untrusted code executed within a NodeVM can exploit the escape. The high exploitability and potential for widespread impact make urgent remediation essential.
OpenCVE Enrichment
Github GHSA