Description
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored, which are exposed on host WebStream prototypes on newer Node.js releases (validated on Node.js v25.8.0). When the embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can obtain the real host symbols via Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and use them as write keys on host stream objects, corrupting host-visible stream state — for example making stream.Readable.isDisturbed() return false for an already-consumed stream. This can bypass host logic that relies on Node's public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a stream is safe to hand to another component. It is not a host code-execution primitive in the reported proof of vulnerability. This is an incomplete fix for the earlier nodejs.* symbol filtering issue. Fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Host stream state compromise and bypass of one‑shot body consumption
Action: Patch Update
AI Analysis

Impact

The flaw stems from vm2 versions 3.11.4 through 3.11.6 performing incomplete filtering of Node.js internal symbols when data crosses the sandbox boundary. The filter list excludes nodejs.stream.disturbed and nodejs.stream.errored, which are present on host WebStream prototypes in recent Node.js releases. When sandbox code can access a host WebStream object, it can enumerate its internal symbols and write to host stream objects using those symbols as property keys. This allows the sandbox to corrupt internal stream flags, such as causing stream.Readable.isDisturbed() to report false after the stream has already been consumed. By tampering with stream state, attacker code can bypass host logic that relies on these helpers to enforce one‑shot body consumption, detect errored streams, or determine stream safety for reuse. The weakness is a classic example of CWE‑669, uncontrolled modification of data structure contents.

Affected Systems

The vulnerability affects the patriksimek:vm2 library in versions 3.11.4, 3.11.5, and 3.11.6. It applies to Node.js environments that expose host WebStream objects and the host stream/web module to the sandbox, as verified against Node.js v25.8.0. All applications that embed these vm2 versions and grant the sandbox access to the relevant host modules are susceptible. The issue was resolved in vm2 3.11.7.

Risk and Exploitability

The CVSS score for this issue is 8.9, indicating high severity. EPSS data is not available, but the outlined exploit path remains significant. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at the time of disclosure. Exploitation requires the ability to run untrusted code inside a vm2 sandbox that has been provided host WebStream objects; it does not grant host code execution but can lead to denial‑of‑service, incorrect message handling, or the ability to misrepresent stream consumption state, thus compromising application integrity.

Generated by OpenCVE AI on September 17, 2026 at 23:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which removes the vulnerable symbol filtering logic.
  • Do not expose host WebStream objects or the host stream/web module to untrusted sandbox code; isolate or remove these references before creating the sandbox.
  • Add application‑level validation around stream consumption and error handling so that security decisions do not rely solely on stream.isDisturbed or similar helpers.

Generated by OpenCVE AI on September 17, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jf8q-945g-9q4c vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-184
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a fixed list of known dangerous registered symbols that omits nodejs.stream.disturbed and nodejs.stream.errored, which are exposed on host WebStream prototypes on newer Node.js releases (validated on Node.js v25.8.0). When the embedder exposes a host WebStream object and the host stream/web module to the sandbox, sandbox code can obtain the real host symbols via Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype) and use them as write keys on host stream objects, corrupting host-visible stream state — for example making stream.Readable.isDisturbed() return false for an already-consumed stream. This can bypass host logic that relies on Node's public stream-state helpers to enforce one-shot body consumption, reject errored streams, or decide whether a stream is safe to hand to another component. It is not a host code-execution primitive in the reported proof of vulnerability. This is an incomplete fix for the earlier nodejs.* symbol filtering issue. Fixed in vm2 3.11.7.
Title vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:44:51.213Z

Reserved: 2026-09-17T12:43:03.568Z

Link: CVE-2026-92952

cve-icon Vulnrichment

Updated: 2026-09-17T15:44:03.693Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:00.987

Modified: 2026-09-17T16:18:34.807

Link: CVE-2026-92952

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T13:46:11Z

Links: CVE-2026-92952 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-669

    Incorrect Resource Transfer Between Spheres