vm2 NodeVM Sandbox Escape via node:test.run() execArgv
A critical vulnerability in vm2, a popular Node.js sandboxing library, allows attackers to escape the sandbox and execute arbitrary JavaScript in the host process. This is achieved by exploiting the node:test module, which can be exposed to sandboxed code when explicitly allowed by the embedder. The vulnerability affects vm2 versions >=3.9.6 and <=3.11.5 on Node.js 24 and newer.