cbcvebase.

Vm2 Project Vm2 vulnerabilities

73 known vulnerabilities affecting vm2_project/vm2.

Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH13MEDIUM10

Vulnerabilities

Page 4 of 4
CVE-2026-44000P3HIGHCVSS 7.2fixed in 3.11.02026-05-13
CVE-2026-44000 [HIGH] CWE-693 CVE-2026-44000: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 a vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox .then() callback preserves host identity. This al
ghsanvd
CVE-2026-92950P3HIGH≥ 0, < 3.11.72026-10-01
CVE-2026-92950 [HIGH] CWE-1188 vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts ### Summary The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver l
ghsa
CVE-2026-92959P3HIGH≥ 0, < 3.11.82026-10-05
CVE-2026-92959 [HIGH] CWE-693 vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM ### Summary When `allowAsync` is set to `false`, vm2 is expected to reject attempts to run asynchronous code. Direct use of `Promise.prototype.then` is blocked, but Promise static methods still assimilate attacker-controlled thenables. `Promise.resolve(thenable)`, `Promise.al
ghsa
CVE-2026-47141P3MEDIUM≥ 0, < 3.11.42026-05-29
CVE-2026-47141 [MEDIUM] CWE-668 NodeVM observability builtins leak host process and HTTP request data NodeVM observability builtins leak host process and HTTP request data ## Summary `NodeVM` exposes some process-wide observability builtins when they are allowed through `require.builtin`. The following builtins are not blocked by the dangerous builtin denylist: ```text diagnostics_channel async_hooks perf_hooks ``` These modules are process-wide, not sandbox-local. Sandboxed code can use th
ghsa
CVE-2026-92952P3MEDIUM≥ 3.11.4, < 3.11.72026-10-01
CVE-2026-92952 [MEDIUM] CWE-669 vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks ## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code. The prior `nodejs.*` symbol hardening blocks `Symbol.for('nodejs.')` at the source, but the
ghsa
CVE-2026-44002P4MEDIUMCVSS 5.8fixed in 3.11.02026-05-13
CVE-2026-44002 [MEDIUM] CWE-209 CVE-2026-44002: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intende vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library p
ghsanvd
CVE-2026-44003P4MEDIUMCVSS 5.8fixed in 3.11.02026-05-13
CVE-2026-44003 [MEDIUM] CWE-693 CVE-2026-44003: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performa vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL variable, which ex
ghsanvd
CVE-2026-100722P4HIGH≥ 0, < 3.12.22026-10-05
CVE-2026-100722 [HIGH] CWE-248 vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process ## Summary An untrusted script run by `VM.run` can construct an embedder-exposed host function that returns a rejected native Promise and ignore the result. The sandbox-to-host `construct` trap forwards that Promise without applying the host-side rejection handling already used by the
ghsa
CVE-2026-92936P3MEDIUM≥ 3.11.0, < 3.11.72026-10-05
CVE-2026-92936 [MEDIUM] CWE-209 vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting ## Summary Attacker-controlled code can trigger a host-realm syntax error and read its stack through the vm2 bridge. Host-realm stack formatting bypasses the sandbox-side redaction, so the returned value exposes absolute paths from vm2, Node.js internals, and the embedding application. Default VM
ghsa
CVE-2026-92933P4MEDIUM≥ 0, < 3.11.82026-10-05
CVE-2026-92933 [MEDIUM] CWE-200 vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack ### Summary NodeVM exposes the host `util` module to the sandbox through an unfiltered shallow copy (`Object.assign({}, util)`). On Node.js >= 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's fu
ghsa
CVE-2023-32313P4MEDIUMCVSS 5.3fixed in 3.9.182023-05-15
CVE-2023-32313 [MEDIUM] CWE-74 CVE-2023-32313: vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lo vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a threat actor can edit options for the `console.log` command. This vulnerability was patched in the release of versio
ghsanvdosv
CVE-2026-92949P4MEDIUM≥ 3.9.6, < 3.11.72026-10-01
CVE-2026-92949 [MEDIUM] CWE-471 vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor ### Summary Untrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is "prevent sandboxed scripts from adding, changing, or deleting properties". If the frozen host object has an accessor
ghsa
CVE-2026-92945P4MEDIUM≥ 0, < 3.11.72026-10-01
CVE-2026-92945 [MEDIUM] CWE-22 vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted ## Summary `isPathAllowedForModule` decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. `node_modules/foo2` starts with `node_modules/foo`, so a package whose name merely shares a
ghsa
Vm2 Project Vm2 vulnerabilities | cvebase