Description
vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated `sys` builtin (an alias of host `util`) is exposed through the generic builtin loader. On Node.js >= 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the `Error.prepareStackTrace` formatting channel. The issue is fixed in vm2 3.11.8.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch now
AI Analysis

Impact

vm2 is a sandbox for running untrusted Node.js code. In versions up to and including 3.11.7, the library exposes the host’s util module as an unfiltered shallow copy and also exposes the deprecated sys builtin, an alias of util. On Node.js 22.9 and later, the sandboxed code can call util.getCallSites, a programmatic stack‑introspection API that returns the host process’s full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application’s entry point. This bypasses host‑frame redaction applied to stack formatting, leading to a disclosure of information about the host environment. The vulnerability is classified as CWE‑200.

Affected Systems

The vulnerability affects the vm2 library published by patriksimek. Versions up to and including 3.11.7 are impacted. The issue is resolved in vm2 3.11.8 and later.

Risk and Exploitability

The CVSS base score of 6.9 indicates a medium severity information‑disclosure vulnerability. EPSS for this issue is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker would need to execute code within the NodeVM sandbox to exploit util.getCallSites; achieving that would typically require prior compromise or exploitation of another weakness that enables arbitrary code execution inside the sandbox. Once in the sandbox, the attacker could retrieve the host process’s full call stack, revealing absolute file paths, function names, and line numbers of the embedding application, which can expose sensitive internal structure or secrets.

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.8 or later
  • If an upgrade is not immediately possible, reconfigure the sandbox to omit the util module or use a custom builtin loader that does not expose util
  • Restrict the sandboxed code from accessing internal APIs such as util.getCallSites by adjusting configuration or runtime checks
  • Audit dependencies to ensure no older vulnerable versions persist

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r273-hxvj-fxhp vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack
History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-497
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated `sys` builtin (an alias of host `util`) is exposed through the generic builtin loader. On Node.js >= 22.9 this hands sandboxed code `util.getCallSites()`, a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the `Error.prepareStackTrace` formatting channel. The issue is fixed in vm2 3.11.8.
Title vm2 before 3.11.8 Information Disclosure via util.getCallSites
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:27:07.171Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92933

cve-icon Vulnrichment

Updated: 2026-09-19T02:27:00.576Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:57.337

Modified: 2026-09-19T03:17:18.310

Link: CVE-2026-92933

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T13:45:59Z

Links: CVE-2026-92933 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere