Executive brief
vm2 is a popular software library used to safely run untrusted code in an isolated 'sandbox' environment. A critical security flaw allows an attacker to break out of this isolation and execute commands directly on the underlying server. This could lead to a complete system takeover, unauthorized data access, and disruption of services.
Technical details
A sandbox escape vulnerability exists in vm2 due to improper control of dynamically-identified variables. Specifically, sandboxed code can reach the 'BaseHandler.getPrototypeOf' method within 'lib/bridge.js', which allows an attacker to retrieve arbitrary prototypes from the host environment. By leveraging these prototypes, an attacker can gain access to host-level constructors (such as 'process') and execute arbitrary system commands. This bypasses the sandbox security boundary entirely. The vulnerability is fixed in version 3.11.0.
Affected products
- patriksimek vm2 < 3.11.0
- Red Hat Self-service automation portal 2 2
Timeline
- 2026-05-01: advisory: Original GitHub security advisory published by maintainer
- 2026-05-13: disclosed: CVE-2026-44006 published to NVD
- 2026-05-13: patched: Fix released in version 3.11.0