Executive brief
vm2 is a JavaScript sandbox library used to safely execute untrusted code in isolation. Versions 3.10.1 through 3.11.6 contain a flaw that allows attackers running code in a default sandbox to escape and access the host Node.js process, including sensitive modules like the file system. An attacker with control over code executed in the sandbox can break out and execute arbitrary code on the host system.
Technical details
The vulnerability is a sandbox escape triggered through WebAssembly.compileStreaming and WebAssembly.instantiateStreaming APIs on Node.js 26. These streaming functions can return a raw host-realm Promise (not proxied through vm2's security boundary) that rejects with a host-realm TypeError. By controlling Symbol.species via Promise.prototype.finally, sandbox code receives the host error object, traverses its constructor chain to reach the host Function constructor, and recovers the real host process object via hostError.constructor.constructor('return process')(). This bypasses vm2's Promise hardening which normally intercepts sandbox-realm Promise objects. The vulnerability requires only the ability to execute arbitrary JavaScript in a default new VM() sandbox; no NodeVM, require permissions, or unsafe host object injection is needed. Fix is available in version 3.11.7.
Affected products
- vm2 vm2 3.10.1 through 3.11.6
Timeline
- 2026-08-24: disclosed
- 2026-09-17: advisory
- 2026: patched: Fix released in vm2 3.11.7