PT-2026-94320 · Npm · Vm2

·

CVE-2026-92949

·

Published

2026-09-17

·

Updated

2026-09-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions vm2 versions 3.9.6 through 3.11.6
Description Insufficient restriction of access to accessor properties on frozen objects allows sandboxed scripts to bypass protections provided by vm.freeze() and vm.readonly(). Attackers can utilize Object.getOwnPropertyDescriptor() or lookupSetter () to extract and invoke host object setters directly, enabling the mutation of properties that were explicitly marked as read-only by the embedder.
Recommendations Update vm2 to version 3.11.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92949
GHSA-633R-HQ9M-C4FF

Affected Products

Vm2