PT-2026-94333 · Npm · Vm2
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.4
Description
vm2 is a sandbox for running untrusted JavaScript. The
defaultSandboxPrepareStackTrace() function in lib/setup-sandbox.js uses prototype-walking index assignment to build its output array instead of a prototype-bypassing define-property primitive. Since this internal array is allocated within the sandbox realm, malicious code can install an accessor on Array.prototype for the relevant index. This accessor is triggered whenever the sandbox reads error.stack or triggers Error.prepareStackTrace(), allowing the sandbox code to observe and intercept each stack-trace line written by the bridge. This issue also affects the error-handling (catch) branch. Because the values written are only formatted strings, the impact is limited to an information side channel and a violation of the bridge-container defense invariant rather than a full sandbox escape.Recommendations
Update vm2 to version 3.11.4 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2