Impact
An untrusted script can escape the vm2 sandbox by invoking a host‑provided non‑strict function without a defined receiver. The bug causes the V8 engine to substitute the host realm’s global object for the function’s this value, which vm2 then returns to the sandbox as a live proxy. The attacker can then access host objects such as process and execute arbitrary code through methods like process.getBuiltinModule('child_process').execSync.
Affected Systems
Products: vm2 (patriksimek:vm2) prior to version 3.12.1. The vulnerability affects Node.js applications that embed vm2 and expose at least one non‑strict host function to the sandbox. The issue was fixed in vm2 3.12.1.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. EPSS < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack model is straightforward: the attacker only needs the application to expose a non‑strict host function. Once that condition is met, the attacker gains Remote Code Execution on the host with no additional prerequisites.
OpenCVE Enrichment