Patriksimek Vm2 vulnerabilities
74 known vulnerabilities affecting patriksimek/vm2.
Total CVEs
74
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL47HIGH15MEDIUM11LOW1
Vulnerabilities
Page 4 of 4
CVE-2026-44000P3HIGHCVSS 7.2fixed in 3.11.02026-05-13
CVE-2026-44000 [HIGH] CWE-693 CVE-2026-44000: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 a
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox .then() callback preserves host identity. This al
nvd
CVE-2026-92959P3HIGHCVSS 7.1fixed in 3.11.82026-09-17
CVE-2026-92959 [HIGH] CWE-693 CVE-2026-92959: vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localP
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled) still assimilate attacker-supplied thenables: nati
nvd
CVE-2026-47141P3MEDIUMCVSS 6.9fixed in 3.11.42026-06-12
CVE-2026-47141 [MEDIUM] CWE-668 CVE-2026-47141: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-w
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The diagnostics_channel, async_hooks, and perf_hooks builtins are not blocked by the dangerous builtin denylist. These modules are process-wide, not sandbox-local. Sandboxed cod
nvd
CVE-2026-92952P3MEDIUMCVSS 6.8≥ 3.11.4, < 3.11.72026-09-17
CVE-2026-92952 [MEDIUM] CWE-669 CVE-2026-92952: vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across th
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored,
nvd
CVE-2026-100722P4MEDIUMCVSS 6.8fixed in 3.12.22026-09-27
CVE-2026-100722 [MEDIUM] CWE-248 CVE-2026-100722: vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host constru
vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.construct without the same sanitization. If an embedder exposes a constructable host function
nvd
CVE-2026-92936P3MEDIUMCVSS 5.8≥ 3.11.0, < 3.11.72026-09-17
CVE-2026-92936 [MEDIUM] CWE-209 CVE-2026-92936: vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through err
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read the error's .stack property; the bridge forwards the .stack read to the ho
nvd
CVE-2026-92933P4MEDIUMCVSS 5.8fixed in 3.11.82026-09-17
CVE-2026-92933 [MEDIUM] CWE-200 CVE-2026-92933: vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host
vm2 is a sandbox for running untrusted Node.js code. In versions = 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypas
nvd
CVE-2026-44002P4MEDIUMCVSS 5.8fixed in 3.11.02026-05-13
CVE-2026-44002 [MEDIUM] CWE-209 CVE-2026-44002: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intende
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library p
nvd
CVE-2026-44003P4MEDIUMCVSS 5.8fixed in 3.11.02026-05-13
CVE-2026-44003 [MEDIUM] CWE-693 CVE-2026-44003: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performa
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL variable, which ex
nvd
CVE-2026-92963P4MEDIUMCVSS 5.3fixed in 3.11.22026-09-17
CVE-2026-92963 [MEDIUM] CWE-227 CVE-2026-92963: vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_
vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.
nvd
CVE-2023-32313P4MEDIUMCVSS 5.3fixed in 3.9.182023-05-15
CVE-2023-32313 [MEDIUM] CWE-74 CVE-2023-32313: vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lo
vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a threat actor can edit options for the `console.log` command. This vulnerability was patched in the release of versio
nvd
CVE-2026-92945P4MEDIUMCVSS 4.2fixed in 3.11.72026-09-17
CVE-2026-92945 [MEDIUM] CWE-22 CVE-2026-92945: vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that us
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing relative requires from allowlisted packages when transitive loading is disabled.
nvd
CVE-2026-92949P4MEDIUMCVSS 4.0≥ 3.9.6, < 3.11.72026-09-17
CVE-2026-92949 [MEDIUM] CWE-471 CVE-2026-92949: vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on fro
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder
nvd
CVE-2026-92962P4LOWCVSS 2.1fixed in 3.11.42026-09-17
CVE-2026-92962 [LOW] CWE-693 CVE-2026-92962: vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the d
vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) rather than a prototype-bypassing define-property primitive. Because this bridge-internal array
nvd
← Previous4 / 4