Impact
vm2 prior to 3.11.6 allows sandbox code configured with the builtins wildcard to access the host's operating system and DNS modules. This omission of access controls leads to information disclosure of host process identity and network topology, while also permitting attackers to globally change the host DNS resolver via dns.setServers(). The result is a combination of confidentiality compromise and potential denial or manipulation of network services.
Affected Systems
The vulnerability affects the vm2 library developed by patriksimek. All releases earlier than 3.11.6 are impacted; users should verify the version they are running and update if necessary.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. Although the EPSS score is not available, the absence of a listed KEV status suggests no confirmed public exploits yet. The likely attack vector is a sandbox developer or a compromised sandboxed script that is constructed with the broad '*'-builtins configuration. An attacker in such a position can read sensitive host information and hijack DNS resolution, resulting in potential data exfiltration or redirection attacks.
OpenCVE Enrichment