GHSA-2vh9-cv26-p97mMedium· 5.8▾ SunlitDuplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-r273-hxvj-fxhp. This link is maintained to preserve external references.
vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host util module to the sandbox as an unfiltered shallow copy (Object.assign({}, util) in defaultBuiltinLoaderUtil), and the deprecated sys builtin (an alias of host util) is exposed through the generic builtin loader. On Node.js >= 22.9 this hands sandboxed code util.getCallSites(), a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the Error.prepareStackTrace formatting channel. The issue is fixed in vm2 3.11.8.
vm2 <= 3.11.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92933Medium· 5.8vm2 is a sandbox for running untrusted Node.js code
GHSA-43rv-jrfh-9mrrMedium· 7.5Duplicate Advisory: vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
GHSA-x5qg-8pq6-39h6Critical· 10.0Duplicate Advisory: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
CVE-2026-100723High· 7.5vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules
CVE-2026-92947Critical· 10.0vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations
GHSA-m5w8-4gq2-6f8xCritical· 10.0vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)