Executive brief
vm2 is a popular Node.js library used to run untrusted code in a restricted 'sandbox' environment to prevent it from accessing the host system. A vulnerability was discovered that allows an attacker to bypass these restrictions and 'escape' the sandbox. If exploited, an attacker can execute unauthorized commands on the underlying server, potentially leading to full system takeover and data theft.
Technical details
A sandbox escape vulnerability exists in vm2 due to improper control of dynamically-managed code resources. By using a specific combination of prototype-mutating methods (such as __lookupGetter__ and __lookupSetter__ on the Buffer object) and triggering specific Node.js errors (ERR_INVALID_ARG_TYPE), an attacker can obtain a reference to the host's TypeError constructor. This allows the attacker to sever the host's prototype chain and access the host-realm Function constructor. The vulnerability can be exploited by any attacker capable of providing code to be executed within the vm2 sandbox. The issue is patched in version 3.11.4 by implementing a blocklist for host prototype-mutating setters and enhancing cache checks during prototype-chain walks.
Affected products
- patriksimek vm2 <= 3.11.3
Timeline
- 2026-05-17: patched: Fix committed to repository
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD