Impact
The vulnerability arises in vm2 3.11.0 through 3.11.6 when attacker-supplied code can trigger a SyntaxError in the host‑realm source transformer. The resulting error stack includes absolute host file system paths, Node.js internals, and the embedding application’s source tree. An attacker can read the stack via the .stack property, exposing directory structures and potentially sensitive deployment information. The flaw is a classic information‑disclosure bug (CWE-209) and does not provide additional privileges or code execution capabilities.
Affected Systems
Affected vendors and products include patriksimek vm2. The component versions 3.11.0 through 3.11.6 are impacted. Both default new VM() and new NodeVM() configurations are subject to the defect, even when string eval is disabled, and the patch was released in version 3.11.7.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium‑severity information disclosure. The EPSS score is not available, but the existence of public advisories suggests that the flaw could be actively exploited. The attack vector requires the attacker to supply malicious code to the sandbox; once the error is triggered, the host stack is revealed in the application’s context, leaking absolute paths. Because there is no code‑execution vector, the risk is limited to data leakage, although revealing deployment structure can aid further attacks.
OpenCVE Enrichment
Github GHSA