External risk intelligence

vm2 Sandbox Escape Allows Host Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-93603

vm2 is a library used by developers to sandbox code within an application, not a standalone internet-facing service, product, or gateway. It is a build-time or internal dependency that requires specific developer implementation to expose functionality to sandboxed code, making direct public-internet exposure of the vulnerable component highly unlikely in standard deployments.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in the vm2 library, affecting applications that use it to sandbox untrusted code. The issue allows sandboxed scripts to escape their environment and execute arbitrary commands on the host system if the application exposes non-strict host functions. This could lead to significant security breaches, including unauthorized access and control of your infrastructure.

  • Unsafe code can escape its sandbox.
  • Critical escape flaw impacts host system control.
  • Assess if your code uses vm2 for untrusted scripts.

Attack Path

How an attacker could exploit the issue

An attacker could compromise an application by leveraging a vulnerability in the vm2 library, which is designed to sandbox code. This vulnerability arises when sandboxed code interacts with a non-strict host function without a proper receiver. By manipulating this interaction, an attacker can gain a live proxy to the host's global objects, effectively breaking out of the sandbox. Once outside, the attacker can access sensitive host functions, such as those for executing commands, leading to arbitrary code execution on the host system.

  • Application must expose non-strict host functions.
  • Sandboxed code calls host function without a receiver.
  • Full sandbox escape and arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a vulnerable vm2 sandbox could allow untrusted script to gain access to the host's global objects, enabling the execution of arbitrary code or commands on the host system. This is possible when the embedding application exposes non-strict host functions to the sandbox, and the sandboxed code calls such a function without a receiver.

  • Host global objects and command execution.
  • Sandboxed code calls a non-strict host function.
  • Arbitrary code execution on the host.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that `vm2` is a sandboxing library integrated into applications, the primary responsibility for addressing this CVE likely lies with the application development team or the platform team managing the application's runtime environment. The initial step should be to inventory all applications that utilize `vm2`, determine if the vulnerable version is in use, and assess whether the specific exploitable condition (exposure of non-strict host functions) exists.

  • Application owners to confirm `vm2` usage.
  • Verify vulnerable `vm2` versions and exposure.
  • Plan application remediation via library updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library?

vm2 is a JavaScript library designed to run untrusted code in an isolated environment, known as a sandbox. Developers use it to execute user-provided scripts safely within their applications without granting those scripts direct access to the underlying system. It serves as an internal dependency rather than a standalone service, acting as a container to restrict what code can see and do.

How does CVE-2026-93603 break the sandbox?

This vulnerability involves a weakness class called CWE-94, which relates to improper control of code generation. The sandbox fails to properly handle specific function calls, allowing a script to obtain a reference to the host system's global environment. Once the script has this proxy, it can bypass restrictions to run unauthorized commands directly on the host machine.

Does any interaction with the sandbox trigger this?

No. The flaw specifically requires the application to expose at least one non-strict, host-provided function to the sandboxed environment. If a sandboxed script calls such a function without a receiver, the sandbox fails to secure the execution. Code running in strict mode or using modern ES module functions is not affected by this specific interaction.

Is my system at risk if vm2 is in my code?

Halo Surface Signal indicates that vm2 is an internal dependency, making direct public-internet exposure of the component very unlikely. Your risk depends on whether your application architecture allows untrusted external input to reach a sandbox that exposes non-strict host functions. If your implementation does not connect these components, the path to exploitation is limited.

What is the first step to address this issue?

Start by identifying every application in your environment that includes vm2 as a dependency. Once you have an inventory, determine if those applications are using a vulnerable version of the library. If they are, prioritize reviewing the code to see if any non-strict host functions are exposed to the sandboxed scripts, then plan to update the library to a patched version.

References