Impact
The vulnerability lies in the sandbox escape mechanism of the vm2 NodeVM package, where the DANGEROUS_BUILTINS denylist fails to block the child_process module. This omission allows an attacker to import child_process and execute arbitrary commands on the host. The impact is the ability for an attacker to run any command with the privileges of the process hosting NodeVM, leading to full system compromise. This weakness falls under CWE-184 and CWE-693, indicating improper authorization failure.
Affected Systems
The affected product is VM2 developed by patriksimek, version 3.12.0 and earlier. All versions before 3.12.1 of the vm2 library are impacted. Applications that instantiate NodeVM with configuration options that permit all builtins (builtin: ['*']) or explicitly allow child_process are at risk.
Risk and Exploitability
The CVSS score of 10 indicates that this flaw is of critical severity. The EPSS score is <1% but the missing child_process block suggests that exploitation is feasible where NodeVM is configured insecurely. This vulnerability is not listed in the CISA KEV catalog, but because it allows arbitrary code execution the likelihood of exploitation in environments that use the insecure configuration is high. Attackers can exploit this flaw by instructing NodeVM to load code that requires child_process, effectively escaping the sandbox.
OpenCVE Enrichment
Github GHSA