Executive brief
vm2 is a JavaScript sandboxing library used to safely execute untrusted code in isolation. When configured with the documented "full builtins" pattern (builtin: ['*']), the sandbox incorrectly exposes the os and dns Node.js modules, allowing an attacker to read sensitive host information (network topology, user credentials, system telemetry) and perform DNS hijacking that affects the entire host process, defeating the sandbox isolation guarantee.
Technical details
This vulnerability is a sandbox escape in vm2's NodeVM due to incomplete module blocklisting. The os and dns builtins are not included in the DANGEROUS_BUILTINS set despite satisfying the same criteria established in GHSA-9g8x-92q2-p28f: they expose and mutate global host-process state that cannot be localized by vm.readonly() proxies. Attack requires NodeVM configuration with builtin: ['*'] (the documented recommended pattern) and no manual -os/-dns exclusions. An attacker controlling sandbox code can call os.userInfo(), os.networkInterfaces(), os.hostname() to exfiltrate host deployment details, and invoke dns.setServers() to perform process-wide DNS hijacking affecting all host outbound network calls. No authentication or user interaction is required. The fix adds os and dns to DANGEROUS_BUILTINS in patched version 3.11.6.
Affected products
- vm2 vm2 <= 3.11.5
Timeline
- 2026-08-17: disclosed
- 2026-08-14: patched: Version 3.11.6