Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in vm2, a Node.js code sandbox, that could allow an attacker to bypass security controls and execute arbitrary commands with the privileges of the host process. The issue arises from how the sandbox handles specific configurations, potentially enabling an escape from the intended sandboxed environment.
- Sandbox could be escaped by attackers.
- Leadership should remember the risk of sandboxes being bypassed.
- Confirm if this sandbox technology is in use.
Attack Path
How an attacker could exploit the issue
An attacker could escape a Node.js sandbox by providing specially crafted input to a sandboxed environment. This involves tricking the sandbox into misinterpreting a `require` option, allowing the attacker to create a new, less restricted sandbox within the original one. This inner sandbox can then be used to execute arbitrary commands on the host system.
- Requires attacker-controlled code execution.
- Triggers when `require` is an array.
- Leads to arbitrary command execution.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, this vulnerability could allow an attacker to execute arbitrary commands with the privileges of the host Node.js process, effectively escaping the sandbox. This occurs when a NodeVM is configured with specific nesting and require options, enabling the attacker to create an inner NodeVM with an allowlist that includes the `child_process` module.
- Host Node.js process commands at risk.
- Attacker-controlled inner VM escapes sandbox.
- Arbitrary command execution by the attacker.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in vm2 impacts applications that use the NodeVM constructor for sandboxing untrusted Node.js code. Typically, application owners or the platform teams responsible for the Node.js runtime environment would lead the remediation efforts. The initial practical step involves identifying all instances of vm2 within the organization's codebase and infrastructure, assessing their reachability and criticality, and then coordinating the update with the vendor or applying the fix during a planned maintenance window.
- Application owners should manage the fix.
- Verify if vm2 is in use.
- Plan coordinated updates or vendor engagement.