PT-2026-94305 · Npm · Vm2

·

CVE-2026-92933

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.8
Description NodeVM exposes the host util module to the sandbox as an unfiltered shallow copy in defaultBuiltinLoaderUtil, and the deprecated sys builtin is exposed through the generic builtin loader. When running on Node.js >= 22.9, sandboxed code can access util.getCallSites(), a programmatic stack-introspection API. This allows the retrieval of the host process's full call stack, including absolute file paths, function names, and line numbers for the embedding application's entrypoint and internal bridge components, bypassing existing host-frame redaction.
Recommendations Update to version 3.11.8.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92933
GHSA-R273-HXVJ-FXHP

Affected Products

Vm2