Npm · Vm2 · CVE-2026-92936
**Name of the Vulnerable Software and Affected Versions**
vm2 versions 3.11.0 through 3.11.6
**Description**
Absolute host filesystem paths are leaked to sandboxed code via error stack formatting. An attacker can force the host-realm source transformer to throw a `SyntaxError` by calling `eval` with malformed source and subsequently reading the `.stack` property of the error. The bridge forwards this read to the host-realm formatter, bypassing host-path redaction. This results in the disclosure of absolute paths from the software, Node.js internals, and the embedding application's source tree, as well as host function names. This issue affects default `new VM()` and `new NodeVM()` configurations and persists even if string eval is disabled. The impact is limited to information disclosure.
**Recommendations**
Update to version 3.11.7.