Executive brief
vm2 is a popular JavaScript sandbox library used to safely execute untrusted code in isolated environments. A flaw in how Promise callbacks are sanitized allows attackers to escape the sandbox and execute arbitrary system commands on the host machine, completely undermining the security isolation that vm2 is designed to provide.
Technical details
vm2 version 3.10.0 and earlier contains a sandbox escape vulnerability in lib/setup-sandbox.js where the Promise.prototype.then callback sanitization is incomplete. While localPromise.prototype.then callbacks are properly sanitized, globalPromise.prototype.then is not—and async functions return globalPromise objects instead of localPromise objects. An unauthenticated attacker can craft malicious code that leverages async functions and Promise.catch() to gain access to the Error constructor, then the Function constructor, enabling execution of arbitrary code with the privileges of the host process. The vulnerability requires no user interaction and is remotely exploitable if vm2 is exposed via a network interface. A patch is available in version 3.10.2.
Affected products
- patriksimek vm2 3.10.0 and earlier; fixed in 3.10.2
Timeline
- 2026-01-26: disclosed
- 2026-01-26: patched: Fixed in version 3.10.2