Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability was discovered in the vm2 sandboxing library, impacting Node.js environments. This issue could allow an attacker to bypass security controls within the sandbox, potentially leading to the execution of arbitrary code on the host system. The main concern is to confirm if our internal development practices or applications utilize this specific library in a manner that exposes this risk.
- Allows code execution outside the sandbox.
- Potentially impacts secure code execution.
- Confirm relevance and exposure for development.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by first gaining limited access to a Node.js application that uses the vm2 sandboxing library. If the application is configured to expose the `node:test` module within the sandbox, the attacker can then craft a specific `require` call to bypass the sandbox's protections. This bypass allows the attacker to execute arbitrary JavaScript code on the host system, effectively breaking out of the sandbox and gaining unrestricted control.
- Requires privileged access to application code.
- Triggered by calling a specific bypassed module.
- Arbitrary code execution on the host.
Live Threat
Current exploitation, exposure, and threat context
A sandbox escape vulnerability in vm2 could allow an attacker to execute arbitrary JavaScript code on the host system when specific conditions are met. This occurs when the vm2 sandbox is configured to allow the `node:test` builtin on Node.js 24 or newer, and the attacker can control the `execArgv` values passed to the test execution process.
- Arbitrary JavaScript execution on host.
- Requires specific sandbox configuration.
- Unrestricted host Node.js process.
Operational Fix
Recommended remediation, mitigation, and detection steps
The primary responsibility for addressing this vulnerability likely falls on the application development teams who utilize the vm2 library within their Node.js applications, particularly those running on Node.js 24 and newer. The immediate first step is to inventory applications using vm2 and identify those where the `node:test` builtin is explicitly allowed in the sandbox configuration. This will help prioritize remediation efforts based on the business criticality and reachability of the affected applications.
- Application development teams own this issue.
- Verify applications using vm2 with `node:test` exposed.
- Plan vendor coordination and apply updates.