Executive brief
vm2 is a popular Node.js library used to run untrusted code in a secure, isolated environment. A flaw in its code processing logic allows sandboxed code to bypass security checks and access internal system variables. While this does not immediately allow a full system takeover, it exposes sensitive internal functions that could be used in more complex attacks to break out of the sandbox.
Technical details
A vulnerability exists in vm2's transformer.js where a regex-based 'fast-path' optimization skips Abstract Syntax Tree (AST) analysis if the code lacks 'catch', 'import', or 'async' keywords. When this fast-path is triggered, the AST visitor responsible for blocking access to the internal state variable 'VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL' is bypassed. This allows an attacker to access internal security functions such as 'handleException', 'wrapWith', and 'import'. Additionally, 'with' statement instrumentation is bypassed, allowing for scope manipulation. The issue is addressed in version 3.11.0 by including 'with' and the internal state name in the fast-path check.
Affected products
- patriksimek vm2 <= 3.10.5
Timeline
- 2026-05-01: disclosed: Advisory published by vendor
- 2026-05-07: advisory: GitHub Advisory published
- 2026-05-11: patched: Version 3.11.0 released