Executive brief
vm2 is a popular JavaScript sandbox library used to safely execute untrusted code in an isolated environment. A flaw in how the library handles exceptions allows attackers to escape the sandbox restrictions and execute arbitrary code with full access to the host system. This could allow an attacker to gain complete control of any application or server running vm2.
Technical details
The vulnerability exists in vm2's exception sanitization logic within the handleException() function. Attackers can raise an unsanitized host exception that bypasses the sandbox boundary, allowing arbitrary code execution in the host context. The attack requires no authentication or user interaction and is exploitable via network if the affected application exposes vm2 functionality remotely. No preconditions prevent exploitation—any code running within the sandbox can trigger the flaw. A public proof-of-concept demonstrating the bypass is available on GitHub, and the vulnerability was fixed in version 3.9.17.
Affected products
- Patriksimek vm2 up to 3.9.16
Timeline
- 2023-04-17: disclosed: Initial disclosure
- 2023-04-20: patched: Fixed in version 3.9.17