Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability in the vm2 JavaScript library, which is used for isolating code. The issue allows attackers to escape the sandbox and potentially execute arbitrary code on the host system if specific conditions related to how Promises are handled are met.
- A library for running untrusted code can be bypassed.
- This could allow an attacker to run malicious code.
- Confirm if this library is used in your environment.
Attack Path
How an attacker could exploit the issue
An attacker could reach this vulnerability by sending a specially crafted promise to a sandboxed environment that exposes host APIs. By manipulating the promise's constructor, an attacker could bypass security controls and execute arbitrary code on the host system.
- No authentication or user interaction required.
- Triggered by a malformed host promise.
- Results in arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
The vm2 sandbox escape vulnerability could allow attackers to execute arbitrary code on the host system when specific conditions related to host API promises are met. This could occur when an application embeds an API that returns a host-realm Promise, and the sandbox's promise handling is not fully applied to these host Promises, potentially exposing sensitive host objects.
- Host API interactions within the sandbox.
- Exploiting host Promise behavior.
- Arbitrary code execution on the host.
Operational Fix
Recommended remediation, mitigation, and detection steps
The vm2 library is a development dependency, meaning ownership typically falls to the application development team responsible for building and maintaining the software that uses it. The first critical step is for development teams to identify where vm2 is integrated into their codebase and assess the risk based on how the sandbox is used and what sensitive host APIs are exposed.
- Application development teams own the issue.
- Verify vm2 usage and sandbox exposure.
- Plan secure updates during maintenance windows.