PT-2026-94305 · Npm · Vm2
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.8
Description
NodeVM exposes the host
util module to the sandbox as an unfiltered shallow copy in defaultBuiltinLoaderUtil, and the deprecated sys builtin is exposed through the generic builtin loader. When running on Node.js >= 22.9, sandboxed code can access util.getCallSites(), a programmatic stack-introspection API. This allows the retrieval of the host process's full call stack, including absolute file paths, function names, and line numbers for the embedding application's entrypoint and internal bridge components, bypassing existing host-frame redaction.Recommendations
Update to version 3.11.8.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2