CVE-2026-92949
published 2026-09-17CVE-2026-92949: vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass…
PriorityP422medium4CVSS 3.1
AVNACHPRNUINSCCNILAN
EPSS
0.25%
16.2th percentile
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | >= 3.9.6 < 3.11.7 | 3.11.7 |
CVSS provenance
nvdv3.14.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
patriksimek vm2 3.9.6/3.11.6 Frozen Object Access Object.getOwnPropertyDescriptor/__lookupSetter__ access control (EUVD-2026-81598)
vuldb·2026-09-21·CVSS 4.0
CVE-2026-92949 [MEDIUM] patriksimek vm2 3.9.6/3.11.6 Frozen Object Access Object.getOwnPropertyDescriptor/__lookupSetter__ access control (EUVD-2026-81598)
A vulnerability has been found in patriksimek vm2 3.9.6/3.11.6 and classified as problematic. This impacts the function Object.getOwnPropertyDescriptor/__lookupSetter__ of the component Frozen Object Access. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-92949. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections.
ghsa_unreviewed·2026-09-17
CVE-2026-92949 [MEDIUM] CWE-471 vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections.
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.
Red Hat
vm2: vm2: Sandbox bypass allows unauthorized data modification.
vendor_redhat·2026-09-17·CVSS 4.0
CVE-2026-92949 [MEDIUM] CWE-807 vm2: vm2: Sandbox bypass allows unauthorized data modification.
vm2: vm2: Sandbox bypass allows unauthorized data modification.
A flaw was found in vm2, a JavaScript sandbox. This vulnerability allows sandboxed scripts to bypass security protections, specifically `vm.freeze()` and `vm.readonly()`, which are designed to prevent unauthorized modifications to objects. An attacker can exploit this by directly accessing and invoking setters for properties intended to be read-only, leading to unauthorized data modification within the sandbox environment.
Statement: This Moderate impact flaw in vm2 allows sandboxed JavaScript code to bypass `vm.freeze()` and `vm.readonly()` protections. An attacker capable of executing scripts within the vm2 sandbox could modify properties intended to be read-only, undermining the integrity of the sandboxed environment. Thi
No detection rules found.
No public exploits indexed.
2026-09-17
Published