PT-2026-94323 · Npm · Vm2
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.4 through 3.11.6
Description
Internal Node.js registered symbols are incompletely filtered across the sandbox boundary. The extraction filters in
lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of dangerous symbols that omits nodejs.stream.disturbed and nodejs.stream.errored. These symbols are exposed on host WebStream prototypes in newer Node.js releases. If an embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can use Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) to obtain these host symbols. By using them as write keys on host stream objects, an attacker can corrupt host-visible stream state, such as causing stream.Readable.isDisturbed() to return false for a consumed stream. This allows bypassing host logic that uses public stream-state helpers to enforce one-shot body consumption, reject errored streams, or determine if a stream is safe for other components.Recommendations
Update vm2 to version 3.11.7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2