CVE-2026-92962
published 2026-09-17CVE-2026-92962: vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in…
PriorityP415low2.1CVSS 4.0
AVLACHATNPRNUINVCNVINVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.17%
6.4th percentile
vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) rather than a prototype-bypassing define-property primitive. Because this bridge-internal array is allocated in the sandbox realm, code inside the sandbox can install an accessor on Array.prototype for the relevant index; the accessor is then invoked whenever the sandbox reads error.stack (or otherwise triggers Error.prepareStackTrace), allowing sandbox code to observe and intercept each stack-trace line written by the bridge. The same pattern is used in the error-handling (catch) branch. The values written are formatted strings only, so the practical impact is limited to an information side channel and a violation of vm2's bridge-container defense invariant rather than a sandbox escape; the vendor rates the issue Low. The issue is fixed in vm2 3.11.4, which installs each entry as an own data property via Reflect.defineProperty.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.4 | 3.11.4 |
CVSS provenance
nvdv4.02.1LOWCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vm2: vm2: Information disclosure via stack trace interception
vendor_redhat·2026-09-17·CVSS 2.1
CVE-2026-92962 [LOW] CWE-915 vm2: vm2: Information disclosure via stack trace interception
vm2: vm2: Information disclosure via stack trace interception
A flaw was found in vm2, a sandbox for running untrusted JavaScript. Malicious code running within the sandbox can exploit a weakness in how stack traces are handled. By manipulating the Array.prototype, an attacker can observe and intercept individual lines of stack traces, leading to an information side channel. This allows for the disclosure of limited internal information, violating the sandbox's intended security boundaries.
Statement: This Low impact information disclosure flaw in vm2 does not affect Red Hat products, as the vulnerable code is not present in shipped versions.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria
GHSA
vm2 is a sandbox for running untrusted JavaScript.
ghsa_unreviewed·2026-09-17
CVE-2026-92962 [LOW] CWE-693 vm2 is a sandbox for running untrusted JavaScript.
vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) rather than a prototype-bypassing define-property primitive. Because this bridge-internal array is allocated in the sandbox realm, code inside the sandbox can install an accessor on Array.prototype for the relevant index; the accessor is then invoked whenever the sandbox reads error.stack (or otherwise triggers Error.prepareStackTrace), allowing sandbox code to observe and intercept each stack-trace line written by the bridge. The same pattern is used in the error-handling (catch) branch. The values written are formatted strings only,
No detection rules found.
No public exploits indexed.
2026-09-17
Published