PT-2026-94321 · Npm · Vm2
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.7
Description
A sandbox escape exists in the CLI tool that enables arbitrary code execution within the host Node.js process. An attacker can provide a malicious script file to the CLI that utilizes
require( filename) to re-execute itself in the host realm. This action bypasses sandbox isolation, granting unauthorized access to host modules such as fs and child process.Recommendations
Update vm2 to version 3.11.7 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2