PT-2026-94333 · Npm · Vm2

·

CVE-2026-92962

·

Published

2026-05-18

·

Updated

2026-09-17

CVSS v4.0

2.1

Low

VectorAV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.4
Description vm2 is a sandbox for running untrusted JavaScript. The defaultSandboxPrepareStackTrace() function in lib/setup-sandbox.js uses prototype-walking index assignment to build its output array instead of a prototype-bypassing define-property primitive. Since this internal array is allocated within the sandbox realm, malicious code can install an accessor on Array.prototype for the relevant index. This accessor is triggered whenever the sandbox reads error.stack or triggers Error.prepareStackTrace(), allowing the sandbox code to observe and intercept each stack-trace line written by the bridge. This issue also affects the error-handling (catch) branch. Because the values written are only formatted strings, the impact is limited to an information side channel and a violation of the bridge-container defense invariant rather than a full sandbox escape.
Recommendations Update vm2 to version 3.11.4 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15027
CVE-2026-92962
GHSA-Q3FM-4WCW-G57X

Affected Products

Vm2