CVE-2026-92952
published 2026-09-17CVE-2026-92952: vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in…
PriorityP340medium6.8CVSS 3.1
AVNACHPRNUINSCCNIHAN
EPSS
0.42%
35.9th percentile
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored, which are exposed on host WebStream prototypes on newer Node.js releases (validated on Node.js v25.8.0). When the embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can obtain the real host symbols via Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and use them as write keys on host stream objects, corrupting host-visible stream state — for example making stream.Readable.isDisturbed() return false for an already-consumed stream. This can bypass host logic that relies on Node's public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a stream is safe to hand to another component. It is not a host code-execution primitive in the reported proof of vulnerability. This is an incomplete fix for the earlier nodejs.* symbol filtering issue. Fixed in vm2 3.11.7.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | >= 3.11.4 < 3.11.7 | 3.11.7 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv4.08.9HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary.
ghsa_unreviewed·2026-09-17
CVE-2026-92952 [HIGH] CWE-669 vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary.
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored, which are exposed on host WebStream prototypes on newer Node.js releases (validated on Node.js v25.8.0). When the embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can obtain the real host symbols via Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and use them as write keys on host stream objects, corrupting host-visible stream state — for example making stream.Readable.isDistu
Red Hat
vm2: vm2: Sandbox Symbol Filtering Bypass leading to Host Stream State Corruption
vendor_redhat·2026-09-17·CVSS 6.8
CVE-2026-92952 [MEDIUM] CWE-184 vm2: vm2: Sandbox Symbol Filtering Bypass leading to Host Stream State Corruption
vm2: vm2: Sandbox Symbol Filtering Bypass leading to Host Stream State Corruption
A flaw was found in vm2. The vm2 sandbox incompletely filters Node.js internal symbols, specifically `nodejs.stream.disturbed` and `nodejs.stream.errored`, across the sandbox boundary. This allows code running within the sandbox to obtain real host symbols and use them to corrupt the host-visible stream state. Consequently, an attacker can bypass host logic that relies on Node.js stream-state helpers, potentially leading to incorrect handling of streams. This vulnerability does not enable host code execution.
Statement: This flaw in vm2 allows sandbox code to corrupt host-visible stream state by bypassing symbol filtering, which can lead to integrity issues in applications relying on Node.js stream-state he
No detection rules found.
No public exploits indexed.
2026-09-17
Published