Impact
vm2 is a sandbox for running untrusted Node.js code. In versions up to and including 3.11.7, the library exposes the host’s util module as an unfiltered shallow copy and also exposes the deprecated sys builtin, an alias of util. On Node.js 22.9 and later, the sandboxed code can call util.getCallSites, a programmatic stack‑introspection API that returns the host process’s full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application’s entry point. This bypasses host‑frame redaction applied to stack formatting, leading to a disclosure of information about the host environment. The vulnerability is classified as CWE‑200.
Affected Systems
The vulnerability affects the vm2 library published by patriksimek. Versions up to and including 3.11.7 are impacted. The issue is resolved in vm2 3.11.8 and later.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium severity information‑disclosure vulnerability. EPSS for this issue is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker would need to execute code within the NodeVM sandbox to exploit util.getCallSites; achieving that would typically require prior compromise or exploitation of another weakness that enables arbitrary code execution inside the sandbox. Once in the sandbox, the attacker could retrieve the host process’s full call stack, revealing absolute file paths, function names, and line numbers of the embedding application, which can expose sensitive internal structure or secrets.
OpenCVE Enrichment
Github GHSA