Impact
The vulnerability resides in vm2, a Node.js sandboxing framework. When an embedder exposes a host API that returns a host-realm Promise, the bridge’s rejection sanitizer only protects sandbox-side Promises; host Promises are not neutralized. A sandboxed script can overwrite the host Promise’s constructor[Symbol.species] and then call then() without an onRejected handler. V8’s internal Thrower then re‑throws the raw rejection value into a resolve/reject closure captured by the attacker. If that rejection value is a host‑pivotable object, such as the process object, the attacker obtains a full‑functional bridge proxy of the host object and can execute arbitrary code on the host process. This results in a sandbox escape and full code execution on the host.
Affected Systems
The flaw affects the npm package patriksimek:vm2, versions 3.12.0 and earlier. Any Node.js application that uses these versions and passes host Promise objects into the vm2 sandbox is vulnerable. Updating to version 3.12.1 or later removes the escape path.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, although the potential impact remains high. The vulnerability is not listed in CISA KEV. The attack requires that an untrusted sandbox be able to see host Promise objects; if such APIs are present, an attacker can inject malicious code to trigger the escape.
OpenCVE Enrichment