Horizon Alert
Summary of the vulnerability and why it matters
The vm2 library, used for safely executing untrusted JavaScript in Node.js environments, has a vulnerability that could allow malicious code to terminate the host process. This issue arises from how promises are handled between the sandbox and the main program, potentially leading to unhandled rejections that crash the system.
- Sandbox code can crash the host process.
- A serious flaw in a common JavaScript sandbox.
- Confirm if this library is used to mitigate risk.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted JavaScript code to a Node.js application that uses the vm2 library. This code will cause the application to process a rejected host promise in a way that leads to an unhandled rejection, ultimately crashing the host process.
- Untrusted code execution in Node.js environment.
- Triggering unhandled promise rejections.
- Denial of service by crashing the host process.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could impact Node.js applications using the vm2 library to execute untrusted JavaScript. When an attacker can control code within the sandbox, they may be able to trigger unhandled promise rejections from host functions. This could lead to the Node.js process terminating unexpectedly, causing a denial of service for the application.
- Node.js host process.
- Ignored host Promise return values.
- Application crash and denial of service.
Operational Fix
Recommended remediation, mitigation, and detection steps
The vm2 library is a development dependency, meaning its ownership and exposure depend on how it's integrated into applications. Application owners or platform teams are likely responsible for managing its use, with security teams involved if it poses a direct risk to production environments. The first step is to identify applications using vm2, assess their criticality and reachability, and then plan remediation.
- Application owners should manage remediation.
- Verify where vm2 is deployed.
- Plan fixes based on identified risks.