Description
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight through to the host call, and V8 substitutes the host realm's global object for `this`. vm2 then wraps and returns that object to the sandbox, giving sandboxed script a live proxy of the host global. This allows a complete sandbox escape: untrusted script can reach `process` and execute arbitrary code/commands on the host (for example via `process.getBuiltinModule('child_process').execSync`). Exploitation requires that the embedding application expose at least one non-strict host function to the sandbox; strict-mode and ES module host functions are not affected.
Published: 2026-09-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An untrusted script can escape the vm2 sandbox by invoking a host‑provided non‑strict function without a defined receiver. The bug causes the V8 engine to substitute the host realm’s global object for the function’s this value, which vm2 then returns to the sandbox as a live proxy. The attacker can then access host objects such as process and execute arbitrary code through methods like process.getBuiltinModule('child_process').execSync.

Affected Systems

Products: vm2 (patriksimek:vm2) prior to version 3.12.1. The vulnerability affects Node.js applications that embed vm2 and expose at least one non‑strict host function to the sandbox. The issue was fixed in vm2 3.12.1.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. EPSS < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack model is straightforward: the attacker only needs the application to expose a non‑strict host function. Once that condition is met, the attacker gains Remote Code Execution on the host with no additional prerequisites.

Generated by OpenCVE AI on September 26, 2026 at 05:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.12.1 or later.
  • Verify that the application does not expose any non‑strict (sloppy‑mode) host functions to the vm2 sandbox; remove or change them to strict mode or wrapped functions.
  • If upgrading is not immediately possible, replace susceptible non‑strict host functions with equivalent strict‑mode wrappers or sandboxed alternatives, and limit the host APIs exposed to the sandboxed code.

Generated by OpenCVE AI on September 26, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

threat_severity

Critical


Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight through to the host call, and V8 substitutes the host realm's global object for `this`. vm2 then wraps and returns that object to the sandbox, giving sandboxed script a live proxy of the host global. This allows a complete sandbox escape: untrusted script can reach `process` and execute arbitrary code/commands on the host (for example via `process.getBuiltinModule('child_process').execSync`). Exploitation requires that the embedding application expose at least one non-strict host function to the sandbox; strict-mode and ES module host functions are not affected.
Title vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function
First Time appeared Vm2 Project
Vm2 Project vm2
Weaknesses CWE-94
CPEs cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Vendors & Products Vm2 Project
Vm2 Project vm2
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:25:29.801Z

Reserved: 2026-09-18T11:00:32.756Z

Link: CVE-2026-93603

cve-icon Vulnrichment

Updated: 2026-09-22T14:25:22.139Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:12.003

Modified: 2026-09-22T15:17:24.040

Link: CVE-2026-93603

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-18T13:20:12Z

Links: CVE-2026-93603 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')