Executive brief
vm2 is a JavaScript sandboxing library used to safely execute untrusted code. A critical flaw allows sandboxed code to access Node.js's SQLite module and load native library extensions, bypassing the sandbox entirely and achieving arbitrary native code execution with the host process's privileges. This could allow an attacker to steal secrets, modify files, or compromise the entire host system.
Technical details
The vulnerability is a sandbox escape in vm2's builtin module allowlisting and module resolution. When node:sqlite is permitted as a builtin (explicitly or via wildcard), the resolver treats any string starting with 'node:' as a core module request. The runtime strips only one 'node:' prefix, allowing a request for 'node:node:sqlite' to resolve to the real node:sqlite module. This module is wrapped with vm.readonly() which blocks property assignment but does not prevent calling methods. An attacker can create an in-memory DatabaseSync with extension loading enabled, call loadExtension() on a native library path (derived from __dirname within the untrusted plugin package), and SQLite loads the library into the host Node.js process and invokes its native entry point, achieving arbitrary native code execution outside the sandbox. The fix is available in vm2 3.11.7.
Affected products
- Filippo Simek vm2 3.11.3 through 3.11.6
Timeline
- 2026-08-24: disclosed: GitHub Security Advisory published
- 2026-09-17: advisory: NVD entry published
- 2026-09-17: patched: vm2 3.11.7 released with fix