PT-2026-94320 · Npm · Vm2
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.9.6 through 3.11.6
Description
Insufficient restriction of access to accessor properties on frozen objects allows sandboxed scripts to bypass protections provided by
vm.freeze() and vm.readonly(). Attackers can utilize Object.getOwnPropertyDescriptor() or lookupSetter () to extract and invoke host object setters directly, enabling the mutation of properties that were explicitly marked as read-only by the embedder.Recommendations
Update vm2 to version 3.11.7 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2