Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kimisecurityteam

#42734of 57,418
6.9Total CVSS
Vulnerabilities · 1
PT-2026-94305
6.9
2026-09-17
Npm · Vm2 · CVE-2026-92933
**Name of the Vulnerable Software and Affected Versions** vm2 versions prior to 3.11.8 **Description** NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy in `defaultBuiltinLoaderUtil`, and the deprecated `sys` builtin is exposed through the generic builtin loader. When running on Node.js >= 22.9, sandboxed code can access `util.getCallSites()`, a programmatic stack-introspection API. This allows the retrieval of the host process's full call stack, including absolute file paths, function names, and line numbers for the embedding application's entrypoint and internal bridge components, bypassing existing host-frame redaction. **Recommendations** Update to version 3.11.8.