Node.js ships a built-in vm module that lets you compile and run JavaScript inside a separate V8 context — and for over a decade, teams have reached for it to run plugin code, user-submitted scripts, CI/CD tasks, and third-party config files "safely." The problem: Node's own documentation states plainly that vm "is not a security mechanism" and "should not be used to run untrusted code." Developers ignore that warning constantly, and the consequences have been severe. The most popular userland wrapper built on top of vm, the vm2 package, was hit with at least four critical sandbox-escape CVEs between August 2022 and August 2023 — including one scoring a perfect CVSS 10.0 — before its maintainers deprecated the project outright in September 2023. This post breaks down why vm-based isolation fails, how attackers actually escape it, and what to run instead if your product executes code you don't control.
Security concerns of using the Node.js VM module as a sandbox
Node's vm module and vm2 were never a security boundary. Four critical CVEs and a 2023 deprecation prove why untrusted-code sandboxes need real isolation.
More on #nodejs-security
View allObject Injection Vulnerabilities in PHP and Node.js
Path Traversal Prevention in JavaScript/Node.js with path...
Insecure Deserialization Prevention in JavaScript: Avoidi...
CVE-2018-3728: Prototype pollution in hoek
Related articles in Application Security
A Link Is Fetched Before Anyone Clicks It
Paste a URL into a chat message and a server fetches it automatically to build a preview card, before anyone reads the message or clicks anything. That fetch consumes a single-use link or a time-limited token just as effectively as the intended recipient would have.
Your Access Review Checks One Node in a Graph
A user's permission listing shows no administrative access. By every direct check, they are ordinary. They can still become an administrator through a permission that looks unrelated, was granted for an unrelated reason, and lets them modify something that leads there.
Just-in-Time Provisioning Moves Trust From a Person to a Claim in a Token
A new employee signs in with SSO for the first time, and your application creates an account and assigns a role based on group claims from the identity provider, with no human in the loop to notice if the claim maps to more access than intended.
Never miss an update
Weekly insights on software supply chain security, delivered to your inbox.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.