Junglewise Threat Intelligence

CVE-2026-93603: vm2 sandbox escape via nullish this receiver

CVE-2026-93603 · Severity: critical · CVSS 10 · Published 2026-09-18

Technologies: Patriksimek Vm2.

Executive brief

vm2 is a JavaScript sandbox library used to safely execute untrusted code in an isolated environment. A critical flaw allows attackers to break out of the sandbox and gain full control of the host system when the embedding application exposes any ordinary (non-strict) function to sandboxed code. An attacker can invoke such functions without a proper receiver context, causing the host's global object to leak back into the sandbox, from which they can access the Node.js process object and execute arbitrary commands on the host machine.

Technical details

The vulnerability is a sandbox escape in vm2's bridge mechanism (lib/bridge.js) caused by improper handling of nullish `this` receivers in the apply trap. When sandboxed code calls a host-provided non-strict function without a receiver (e.g., bare call `fn()`, detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()`), the undefined receiver is passed through to the host function call. V8 then substitutes the host realm's global object as `this`, which vm2 wraps and returns to the sandbox as a live proxy. This grants the attacker direct access to the host global object and, critically, to `process.getBuiltinModule('child_process').execSync()` for arbitrary code execution. The attack requires that the embedding application expose at least one non-strict host function to the sandbox; strict-mode and ES module host functions are not affected. A patch is available in version 3.12.1, which replaces nullish receivers with a cached host-realm null-prototype object before invoking the host function, preventing the global object from being exposed.

Affected products

  • Patriksimek vm2 through 3.12.0

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Fixed in version 3.12.1

References