Dev News Daily ENDE

vm2 gets 14 advisories in one evening, eight critical; the fixes end in version 3.12.2

Fourteen security advisories for vm2, a Node.js library for running untrusted JavaScript in a sandbox, were published in the GitHub Advisory Database within an hour on the evening of 5 October (22:34–23:24 UTC). Eight are rated critical, three high and three medium. Several carry a CVSS score of 10.0.

Three groups of fixes. The advisories are fixed in three releases: five in 3.11.7, six in 3.11.8 and three in 3.12.2. Every affected range ends at or below 3.12.1, so 3.12.2 is the version that closes all fourteen.

vm2 gets 14 advisories in one evening, eight critical; the fixes end in version 3.12.2
vm2 gets 14 advisories in one evening, eight critical; the fixes end in version 3.12.2 — Dev News Daily

What the bugs do. The common thread is code inside the sandbox reaching the host:

  • Sandbox escape in NodeVM (GHSA-88hf-g992-jg85, critical, fixed in 3.11.8) and escapes through a host-wrapped AggregateError and through a WebAssembly.compileStreaming promise path.
  • Host memory. In one advisory sandboxed code can read and write host-realm memory through Node's shared Buffer pool; in another, an application that allows the zlib builtin hands the guest a pooled host buffer, through which it can read bytes outside the result and change an unrelated host buffer.
  • Path checks. With custom module resolution, the allowlist stored a resolved path as a prefix without a separator, so a sibling such as foo2/index.js passed the check meant for foo (CVSS 10.0, fixed in 3.12.2). A related advisory covers require.external without an explicit require.root, which granted unrestricted host access.
  • Broken switches and crashes. allowAsync: false could be bypassed through Promise static methods that assimilate thenables; the timeout option could be bypassed through a FinalizationRegistry callback; and a rejected Promise returned from an exposed host constructor could terminate the host process under Node's strict unhandled-rejection policy.

The reports credit more than a dozen researchers; five of the fourteen, including the newest, name rexpository.

What to do. Applications that run untrusted code with vm2 should move to 3.12.2. Several of the issues depend on configuration — which builtins are exposed, how require is set up, what host functions are passed in — so it is also worth re-checking what the sandbox is given.

Primary source
GitHub Advisory Database
https://github.com/advisories/GHSA-88hf-g992-jg85