Executive brief
isolated-vm is a Node.js library used to create secure, isolated environments for running untrusted code. A vulnerability in how the library handles cached data allows an attacker to bypass these security boundaries. If an application accepts malicious data from a user, the attacker can escape the sandbox and execute arbitrary commands on the underlying server, potentially leading to full system compromise.
Technical details
The isolated-vm library (versions 4.3.6 and prior) fails to properly validate V8 cached data passed through the CachedDataOptions API. Because V8 cached data can contain compiled machine code, an attacker who can provide a malicious 'cachedData' payload can bypass the sandbox isolation. This allows for arbitrary code execution within the main Node.js process. The vulnerability is addressed in version 4.3.7, which updates documentation to warn against accepting untrusted cachedData; however, the core issue stems from the inherent nature of V8's serialized data. Users are advised to never pass user-supplied buffers to the CachedDataOptions API.
Affected products
- laverdet isolated-vm <= 4.3.6
Timeline
- 2022-09-29: advisory: Initial disclosure and NVD publication
- 2022-09-30: patched: Version 4.3.7 released with documentation warnings and security notes
References
- https://github.com/laverdet/isolated-vm/security/advisories/GHSA-2jjq-x548-rhpv
- https://github.com/laverdet/isolated-vm/issues/379
- https://github.com/laverdet/isolated-vm/commit/218e87a6d4e8cb818bea76d1ab30cd0be51920e8
- https://github.com/laverdet/isolated-vm
- https://github.com/laverdet/isolated-vm/commits/v4.3.7