Impact
The vulnerability allows code running inside a default vm2 VM to escape the sandbox and gain host access. By exploiting the interaction between WebAssembly.compileStreaming or instantiateStreaming, a sandboxed promise can return a native host error that, when its species is manipulated through Promise.prototype.finally, allows traversal through the host Function constructor to the process object. This results in the ability to require native modules such as fs, execute arbitrary commands, and compromise the entire Node.js application and underlying operating system.
Affected Systems
All vm2 releases from 3.10.1 to 3.11.6 run on Node.js 26 are affected when a new VM is created with default settings. The vendor is patriksimek:vm2 and the exploitation does not require special configuration, permissions, or host object injection.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. No EPSS score is published, but the flaw does not demand privileged context or additional configuration, making exploitation potentially straightforward for an attacker who can supply sandbox code. The vulnerability is not listed in the CISA KEV catalog, yet its reliance on a core Node.js feature makes it a high-priority risk for any production environment that uses vm2.
OpenCVE Enrichment
Github GHSA