Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a security vulnerability in the vm2 sandboxing library that could allow untrusted code running within a sandbox to execute arbitrary commands on the host system. While the library has mechanisms to restrict access to built-in modules, a flaw in how it handles certain prefixed module names means these restrictions can be bypassed, potentially leading to unauthorized command execution.
- Untrusted code can bypass restrictions.
- A bypass could allow host command execution.
- Confirm relevance and review usage of the library.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by crafting malicious code that, when executed within a sandboxed environment, bypasses security restrictions related to Node.js built-in modules. This bypass allows the sandboxed code to access and execute host system commands, effectively gaining control over the underlying machine. The vulnerability stems from how the vm2 library handles negative wildcard entries in its require policy, specifically when dealing with `node:`-prefixed module specifiers.
- Requires unauthenticated access to sandboxed code.
- Triggers when sandboxed code requires specific Node.js modules.
- Risk of host command execution.
Live Threat
Current exploitation, exposure, and threat context
Untrusted code within a sandboxed environment could execute arbitrary host commands by bypassing security policies intended to restrict access to Node.js built-in modules. This could occur when the sandboxing library incorrectly handles specially crafted module requests, allowing access to sensitive APIs.
- Arbitrary host command execution.
- Bypassing security policy restrictions.
- Complete host system compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts applications using the vm2 library for sandboxing, potentially allowing code within the sandbox to execute host commands. Application owners and platform teams are likely responsible for managing this risk, as it involves a developer dependency. The first practical step is to identify all instances of the affected vm2 version, assess their exposure and criticality, and coordinate remediation with development teams and potentially the vendor.
- Application owners must prioritize remediation.
- Verify vm2 usage and version in sandboxed environments.
- Plan maintenance or vendor coordination for updates.