PT-2026-94331 · Npm · Vm2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.6
Description
When the
builtin: ['*'] configuration is used, the software fails to restrict access to the os and dns built-in modules. This allows code running within the sandbox to access process-wide observability data and mutate the state of the host process. Specifically, an attacker can use os.userInfo() to read the host process owner's identity (UID, GID, username, and home directory) and os.networkInterfaces() to disclose the full host network topology, including IP and MAC addresses.Furthermore, the sandbox can perform unauthorized writes to the host process. Using the
os.setPriority() function, an attacker can change the host process priority. Most critically, by invoking the dns.setServers() function, an attacker can globally hijack the host process DNS resolver. This redirects all subsequent DNS queries made by the host—including outbound HTTP requests, telemetry, and package registry lookups—through a resolver controlled by the attacker, potentially leading to credential theft or supply chain attacks.Recommendations
Update vm2 to version 3.11.6 or later.
As a temporary mitigation, avoid using the
builtin: ['*'] configuration and instead explicitly list only the required built-in modules, ensuring that os and dns are excluded.
Restrict the use of the os.setPriority() and dns.setServers() functions within the sandbox environment.Exploit
Fix
Information Disclosure
Incorrect Permission
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2