GHSA-9f3g-34x8-92jcMedium· 4.0▾ SunlitDuplicate Advisory: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-633r-hq9m-c4ff. This link is maintained to preserve external references.
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or lookupSetter() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.
vm2 >= 3.9.6, <= 3.11.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92949Medium· 4.0vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections
GHSA-xq74-c7jx-8w5jCritical· 10.0Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store
GHSA-8mvv-mcc3-xwhhLow· 4.2Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
GHSA-6jgm-4w45-vh8jCritical· 9.9Duplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-3f84-vwv5-r42gCritical· 10.0Duplicate Advisory: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection