Npm · Vm2 · CVE-2026-92933
**Name of the Vulnerable Software and Affected Versions**
vm2 versions prior to 3.11.8
**Description**
NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy in `defaultBuiltinLoaderUtil`, and the deprecated `sys` builtin is exposed through the generic builtin loader. When running on Node.js >= 22.9, sandboxed code can access `util.getCallSites()`, a programmatic stack-introspection API. This allows the retrieval of the host process's full call stack, including absolute file paths, function names, and line numbers for the embedding application's entrypoint and internal bridge components, bypassing existing host-frame redaction.
**Recommendations**
Update to version 3.11.8.