Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the vm2 library, specifically affecting how it handles WebAssembly code within Node.js environments. This issue allows malicious code to escape the intended sandbox, potentially granting unauthorized access to the underlying system. The main concern is confirming if this library is in use and if it is exposed to untrusted code execution.
- Sandbox escape in JavaScript processing library.
- Allows unauthorized system access via WebAssembly.
- Confirm relevance and exposure of the library.
Attack Path
How an attacker could exploit the issue
An attacker can escape the vm2 sandbox by leveraging a flaw in how WebAssembly streaming compilation handles errors. When running on Node.js, the sandbox can be tricked into returning a host-realm error object. By manipulating the Promise behavior, this error can be traced back to the host `Function` constructor, ultimately exposing the real Node.js `process` object and allowing the attacker to execute arbitrary code with host capabilities.
- No special permissions required to start.
- Triggered by specific WebAssembly operations.
- Grants access to host system capabilities.
Live Threat
Current exploitation, exposure, and threat context
The vm2 sandbox, when used with Node.js, could allow an attacker to escape the sandbox environment. This escape is possible when WebAssembly functions are used, enabling malicious code to access host Node.js capabilities, such as file system access, by manipulating Promise behavior to recover the `process` object. This bypasses previous security measures and can occur without requiring specific unsafe configurations.
- Host Node.js capabilities and modules.
- Sandbox escape via WebAssembly streaming.
- Access to host system resources.
Operational Fix
Recommended remediation, mitigation, and detection steps
The vm2 library, used for sandboxing JavaScript execution, has a critical sandbox escape vulnerability. Teams responsible for Node.js applications, especially those processing untrusted code, should prioritize identifying deployments of this library. The immediate next step is to confirm the presence and reachability of affected versions, determine business criticality, and assign ownership for remediation planning.
- Identify application owners and affected code.
- Verify exposure and impact of vulnerable versions.
- Plan remediation or implement controls.