Impact
The bug in vm2 up to version 3.11.6 allows a sandboxed program to bypass a deny list when loading built‑in modules. Because NodeVM removes the 'node:' prefix during runtime resolution but compares deny entries against the canonical names, a policy such as '-node:child_process' fails to block access to the real 'child_process' builtin. The attacker can then import this module and invoke process‑spawning functions such as execSync or spawn, giving host command‑execution capabilities. This is an access‑control failure identified as CWE‑269.
Affected Systems
All installations of the patriksimek vm2 package with a working directory that includes a NodeVM configuration that attempts to deny 'node:child_process' on builtin modules. The vulnerability exists in all releases through 3.11.6 and is resolved in version 3.11.7 and later.
Risk and Exploitability
The CVSS score of 9.4 marks the flaw as critical. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: any untrusted code executed within a NodeVM can exploit the bypass to load the child_process builtin, spawn system processes, and potentially escape the sandbox. Because the bug occurs at runtime, no special conditions beyond possessing a NodeVM configuration with a deny list are required.
OpenCVE Enrichment
Github GHSA