Impact
The flaw stems from vm2 versions 3.11.4 through 3.11.6 performing incomplete filtering of Node.js internal symbols when data crosses the sandbox boundary. The filter list excludes nodejs.stream.disturbed and nodejs.stream.errored, which are present on host WebStream prototypes in recent Node.js releases. When sandbox code can access a host WebStream object, it can enumerate its internal symbols and write to host stream objects using those symbols as property keys. This allows the sandbox to corrupt internal stream flags, such as causing stream.Readable.isDisturbed() to report false after the stream has already been consumed. By tampering with stream state, attacker code can bypass host logic that relies on these helpers to enforce one‑shot body consumption, detect errored streams, or determine stream safety for reuse. The weakness is a classic example of CWE‑669, uncontrolled modification of data structure contents.
Affected Systems
The vulnerability affects the patriksimek:vm2 library in versions 3.11.4, 3.11.5, and 3.11.6. It applies to Node.js environments that expose host WebStream objects and the host stream/web module to the sandbox, as verified against Node.js v25.8.0. All applications that embed these vm2 versions and grant the sandbox access to the relevant host modules are susceptible. The issue was resolved in vm2 3.11.7.
Risk and Exploitability
The CVSS score for this issue is 8.9, indicating high severity. EPSS data is not available, but the outlined exploit path remains significant. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at the time of disclosure. Exploitation requires the ability to run untrusted code inside a vm2 sandbox that has been provided host WebStream objects; it does not grant host code execution but can lead to denial‑of‑service, incorrect message handling, or the ability to misrepresent stream consumption state, thus compromising application integrity.
OpenCVE Enrichment
Github GHSA