Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in the vm2 library, a tool used to create secure sandboxes for running untrusted code. The issue allows code within the sandbox to execute commands on the host system with the authority of the host process, potentially leading to unauthorized native code execution. While the library is designed for security, this flaw bypasses its protections when specific functionalities are enabled.
- Sandbox escape allows host code execution.
- Critical vulnerability in a widely used security tool.
- Verify if this library is used in your applications.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by leveraging the Node.js crypto module within the vm2 sandbox. If the crypto module is permitted, an attacker can call `crypto.setEngine()` with a path to a malicious native library. This library will then execute with host-process authority, allowing the attacker to escape the sandbox and run arbitrary native code.
- Requires access to the crypto builtin.
- Calls `crypto.setEngine()` with a malicious library.
- Leads to sandbox escape and code execution.
Live Threat
Current exploitation, exposure, and threat context
When the `crypto` builtin is exposed within a Node.js environment, an attacker could potentially execute arbitrary native code on the host system. This occurs when sandboxed JavaScript code calls the `crypto.setEngine()` function, allowing the loading and execution of a malicious native library.
- Host process authority and native code.
- Exploited via exposed `crypto` builtin.
- Arbitrary native code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The vm2 library's vulnerability requires investigation by teams responsible for applications that use it for sandboxing, particularly if they permit the crypto builtin and load untrusted code. The first practical move is to identify all instances of affected vm2 versions, assess their reachability and criticality, and then determine the accountable application owner to plan remediation.
- Application owners should address this issue.
- Verify crypto builtin and untrusted code loading.
- Plan remediation based on identified risk.