Impact
The vulnerability allows sandboxed code to import 'fs/promises' even when the standard builtin denylist is intended to block access to the 'fs' module. This bypass results in the exposed promise‑based filesystem API, permitting file creation, deletion, and other filesystem operations within the VM. The consequence is that a sandboxed script can read or modify host files, potentially leading to data compromise or further code execution.
Affected Systems
The issue affects the vm2 library maintained by patriksimek. All versions through 3.11.6 are impacted; the vulnerability is mitigated in release 3.11.7 onwards. Any application that embeds vm2 and configures the built‑in denylist (e.g., require: { builtin: ['*', '-fs', '-child_process']}) is at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. EPSS is currently not available, but the lack of a KEV listing does not diminish the potential exploitation path: an attacker controlling sandboxed code can once the bypass is in place perform privileged file operations. The actual attack vector requires that the host application uses the built‑in denylist and allows the sandbox to import modules. Given the fixed nature in newer releases, this represents a well‑understood, but currently exploitable flaw.
OpenCVE Enrichment
Github GHSA