PT-2026-38388 · Npm · Vm2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.0
Description
A flaw in the Node.js sandbox library allows sandboxed code to obtain the host
Object. This occurs due to incorrect code generation management and incomplete protections. An attacker can use the host Object to bypass isolation and execute arbitrary code on the host system. One method of exploitation involves using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom).Recommendations
Update vm2 to version 3.11.0.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2