here exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass 'handleException()' and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context.