Description
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read the error's .stack property; the bridge forwards the .stack read to the host-realm formatter, bypassing the sandbox-side host-path redaction introduced for GHSA-v27g-jcqj-v8rw. The returned stack string discloses absolute paths from vm2, Node.js internals, and the embedding application's own source tree, along with host function names. Default new VM() and new NodeVM() configurations are affected without any special options, and the issue persists when string eval is disabled because the host-side transformer throws before eval is handled. The impact is information disclosure only; no code execution results. Fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in vm2 3.11.0 through 3.11.6 when attacker-supplied code can trigger a SyntaxError in the host‑realm source transformer. The resulting error stack includes absolute host file system paths, Node.js internals, and the embedding application’s source tree. An attacker can read the stack via the .stack property, exposing directory structures and potentially sensitive deployment information. The flaw is a classic information‑disclosure bug (CWE-209) and does not provide additional privileges or code execution capabilities.

Affected Systems

Affected vendors and products include patriksimek vm2. The component versions 3.11.0 through 3.11.6 are impacted. Both default new VM() and new NodeVM() configurations are subject to the defect, even when string eval is disabled, and the patch was released in version 3.11.7.

Risk and Exploitability

The CVSS score of 6.9 classifies the issue as medium‑severity information disclosure. The EPSS score is not available, but the existence of public advisories suggests that the flaw could be actively exploited. The attack vector requires the attacker to supply malicious code to the sandbox; once the error is triggered, the host stack is revealed in the application’s context, leaking absolute paths. Because there is no code‑execution vector, the risk is limited to data leakage, although revealing deployment structure can aid further attacks.

Generated by OpenCVE AI on September 17, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to v3.11.7 or later.
  • Remove any code paths that enable host‑side stack traces to be forwarded; configure logging to scrub stack traces.
  • Run dependency audit tools and verify that the patched version is present in all deployment environments.

Generated by OpenCVE AI on September 17, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x6m4-chr9-cg97 vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-497
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read the error's .stack property; the bridge forwards the .stack read to the host-realm formatter, bypassing the sandbox-side host-path redaction introduced for GHSA-v27g-jcqj-v8rw. The returned stack string discloses absolute paths from vm2, Node.js internals, and the embedding application's own source tree, along with host function names. Default new VM() and new NodeVM() configurations are affected without any special options, and the issue persists when string eval is disabled because the host-side transformer throws before eval is handled. The impact is information disclosure only; no code execution results. Fixed in vm2 3.11.7.
Title vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:52:18.255Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92936

cve-icon Vulnrichment

Updated: 2026-09-17T15:52:14.277Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:58.320

Modified: 2026-09-17T16:18:34.377

Link: CVE-2026-92936

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T13:46:01Z

Links: CVE-2026-92936 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information

  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere