PT-2026-94310 · Npm · Vm2
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.3 through 3.11.6
Description
When the
builtin: ['*'] configuration or explicit permission is granted, the host node:sqlite module is exposed to code running in NodeVM. Although the module is wrapped with vm.readonly() to prevent property assignment, host-authority callables remain reachable. A flaw in the resolver allows a request for node:node:sqlite to resolve to the node:sqlite entry because the runtime only strips one node: prefix. This enables sandboxed code to create an in-memory DatabaseSync with extension loading enabled and execute DatabaseSync.loadExtension() on a native library. Consequently, the library is loaded into the Node.js host process, allowing arbitrary native code execution with the privileges of the host process.Recommendations
Update to version 3.11.7.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2