CVE-2026-92933
published 2026-09-17CVE-2026-92933: vm2 is a sandbox for running untrusted Node.js code. In versions = 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API…
PriorityP434medium5.8CVSS 3.1
AVNACLPRNUINSCCLINAN
EPSS
0.27%
19.6th percentile
vm2 is a sandbox for running untrusted Node.js code. In versions = 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the `Error.prepareStackTrace` formatting channel. The issue is fixed in vm2 3.11.8.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.8 | 3.11.8 |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 is a sandbox for running untrusted Node.js code.
ghsa_unreviewed·2026-09-17
CVE-2026-92933 [MEDIUM] CWE-200 vm2 is a sandbox for running untrusted Node.js code.
vm2 is a sandbox for running untrusted Node.js code. In versions = 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the `Error.prepareStackTrace` formatting channel. The issue is fixed in vm2 3.11.8.
Red Hat
vm2: vm2: Information Disclosure via util.getCallSites
vendor_redhat·2026-09-17·CVSS 5.8
CVE-2026-92933 [MEDIUM] CWE-497 vm2: vm2: Information Disclosure via util.getCallSites
vm2: vm2: Information Disclosure via util.getCallSites
A flaw was found in vm2. The NodeVM component exposes the host `util` module, including the `util.getCallSites()` function, to the sandbox as an unfiltered copy. On Node.js versions 22.9 and later, this allows sandboxed code to access `util.getCallSites()`, which can return the host process's full call stack. This information disclosure includes sensitive details such as absolute file paths, function names, and line numbers, bypassing existing host-frame redaction mechanisms.
Statement: This Moderate severity flaw in `vm2` allows a sandboxed Node.js environment to disclose sensitive host process information, including file paths and function names. This bypasses existing stack frame redaction, potentially exposing internal applicatio
No detection rules found.
No public exploits indexed.
2026-09-17
Published