Executive brief
vm2 is a JavaScript sandboxing library used to safely execute untrusted code in isolated environments. This vulnerability allows sandbox escape when Node.js 24+ is used and the node:test builtin module is explicitly allowed. An attacker who can run JavaScript within the sandbox can exploit a prefix-stripping logic flaw to access the host node:test module, then call its process spawning API with arbitrary command-line arguments to execute unrestricted code on the host system with full filesystem, network, and process permissions.
Technical details
The vulnerability is a sandbox bypass caused by a combination of three design flaws: (1) Node.js 24+ exposes a scheme-only builtin module key 'node:test' that is not covered by vm2's DANGEROUS_BUILTINS family-based protection; (2) when explicitly allowed by the embedder, this module is stored in the generic host-passthrough loader; (3) requireImpl() in lib/setup-node-sandbox.js normalizes module paths by stripping a single 'node:' prefix, so sandbox code calling require('node:node:test') resolves to the stored 'node:test' key. The attacker receives a readonly proxy to the host module and can invoke node:test.run() with attacker-controlled execArgv parameters, including --eval=<code>, which spawns an unrestricted Node process with full host privileges. The vulnerability requires Node.js 24+, the explicit configuration of require:{builtin:['node:test']}, and the attacker to execute code within the sandbox. A proof-of-concept demonstrates host RCE. Fixed in version 3.11.7.
Affected products
- vm2 vm2 >=3.9.6, <=3.11.6
Timeline
- 2026-08-24: disclosed: Security advisory published on GitHub
- 2026-09-17: advisory: NVD and public advisory posted
- 2026-09-17: patched: vm2 3.11.7 released with fix