Horizon Alert
Summary of the vulnerability and why it matters
This advisory highlights a critical vulnerability in a JavaScript sandbox library, vm2. The issue allows attackers to execute arbitrary commands on the host operating system when specific features are enabled, posing a significant risk if the library is used in applications processing untrusted code or templates. The main concern is confirming relevance and exposure within your environment.
- Library allows code execution on host.
- Potential for broad impact in web applications.
- Confirm use and exposure to assess risk.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by leveraging the `require.external` feature in a sandboxed environment without proper restrictions. If the `vm2` library is used in an application that allows executing untrusted code, and `require.external` is enabled without explicitly excluding `node_modules`, the attacker can trick the sandbox into loading `vm2` itself. This allows them to create an unrestricted `NodeVM` instance, which can then execute arbitrary operating system commands.
- Remote unauthenticated access is required.
- Sandboxed code triggers the vulnerability.
- Arbitrary host OS command execution is possible.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow arbitrary commands to be executed on the host operating system when the `require.external` feature is enabled without proper configuration in the vm2 sandboxing library. This could occur when sandboxed code is able to bypass restrictions and leverage the `child_process` module.
- Host OS command execution.
- Sandboxed code bypasses restrictions.
- Compromise of the underlying host system.
Operational Fix
Recommended remediation, mitigation, and detection steps
The vm2 library's remote code execution vulnerability requires careful consideration of application architecture. Teams responsible for applications that sandbox untrusted code or process user-supplied templates should prioritize identifying instances of vm2, assessing their exposure, and confirming ownership for remediation. The first practical step involves locating all deployments of the affected technology, determining their business criticality and reachability, and assigning accountability for managing the risk.
- Application owners must be identified.
- Verify sandbox code execution paths.
- Plan remediation based on risk.