GHSA-hmpr-c9rf-qcrfHigh· 6.8▾ TwilightDuplicate Advisory: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-jf8q-945g-9q4c. This link is maintained to preserve external references.
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored, which are exposed on host WebStream prototypes on newer Node.js releases (validated on Node.js v25.8.0). When the embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can obtain the real host symbols via Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and use them as write keys on host stream objects, corrupting host-visible stream state — for example making stream.Readable.isDisturbed() return false for an already-consumed stream. This can bypass host logic that relies on Node's public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a stream is safe to hand to another component. It is not a host code-execution primitive in the reported proof of vulnerability. This is an incomplete fix for the earlier nodejs.* symbol filtering issue. Fixed in vm2 3.11.7.
vm2 >= 3.11.4, <= 3.11.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92952Medium· 6.8vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary
GHSA-xq74-c7jx-8w5jCritical· 10.0Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store
GHSA-8mvv-mcc3-xwhhLow· 4.2Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
GHSA-6jgm-4w45-vh8jCritical· 9.9Duplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-3f84-vwv5-r42gCritical· 10.0Duplicate Advisory: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection