---
id: GHSA-9f3g-34x8-92jc
title: >-
  Duplicate Advisory: vm2: vm.freeze()/vm.readonly() bypass via accessor
  descriptor
summary: >-
  Duplicate Advisory: vm2: vm.freeze()/vm.readonly() bypass via accessor
  descriptor
severity: medium
cvss: 4
cwe:
  - CWE-471
vendor: vm2
product: vm2
ecosystem: npm
affected:
  - 'vm2 >= 3.9.6, <= 3.11.6'
published: '2026-09-17'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:35:14Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-9f3g-34x8-92jc'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-633r-hq9m-c4ff'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92949'
  - url: >-
      https://www.vulncheck.com/advisories/vm2-3.9.6-before-3.11.7-sandbox-bypass-via-accessor-descriptor
  - url: 'https://github.com/advisories/GHSA-9f3g-34x8-92jc'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.824Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-633r-hq9m-c4ff. This link is maintained to preserve external references.

## Original Description
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.

## Affected packages

- `vm2 >= 3.9.6, <= 3.11.6`

## Remediation

Refer to the advisory for the patched release.
