Description
vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) rather than a prototype-bypassing define-property primitive. Because this bridge-internal array is allocated in the sandbox realm, code inside the sandbox can install an accessor on Array.prototype for the relevant index; the accessor is then invoked whenever the sandbox reads error.stack (or otherwise triggers Error.prepareStackTrace), allowing sandbox code to observe and intercept each stack-trace line written by the bridge. The same pattern is used in the error-handling (catch) branch. The values written are formatted strings only, so the practical impact is limited to an information side channel and a violation of vm2's bridge-container defense invariant rather than a sandbox escape; the vendor rates the issue Low. The issue is fixed in vm2 3.11.4, which installs each entry as an own data property via Reflect.defineProperty.
Published: 2026-09-17
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade
AI Analysis

Impact

The vulnerability lies in the vm2 library’s stack‑trace preparation routine, which incorrectly populates an array using prototype walking instead of securely defining properties. This flaw permits code inside a sandbox to install a custom accessor on Array.prototype for the specific index used while constructing a stack trace. When the sandbox code triggers Error.prepareStackTrace or accesses error.stack, the accessor fires and exposes each line of the stack trace to the sandbox environment. Consequently, an attacker can read internal call paths, creating an information side channel. According to the CWE classification, this weakness is identified as CWE‑693: Protection Mechanism Failure, and the vendor rates the issue’s severity as low.

Affected Systems

The issue affects the vm2 package from patriksimek, specifically all releases up to and including v3.11.3. The problem originates in lib/setup-sandbox.js and is eliminated in vm2 v3.11.4, where a proper own property definition is used for each stack‑trace entry.

Risk and Exploitability

With a CVSS score of 2.1, the vulnerability is considered low severity. No EPSS data is available, and the flaw is not present in the CISA KEV catalog. The side‑channel nature of the attack reduces the overall risk; an adversary would need to execute untrusted code in a sandbox and rely on stack‑trace access to harvest useful information. The lack of a known exploitation vector in the wild further limits immediate risk.

Generated by OpenCVE AI on September 17, 2026 at 21:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.4 or newer, which replaces the unsafe array assignment with a secure Reflect.defineProperty call.
  • If upgrading is not yet possible, do not run untrusted JavaScript via vm2 until the patch is applied or isolate the sandboxed code in a separate process with stricter permissions.
  • Configure error handling to suppress Error.prepareStackTrace or ensure sandbox code does not read error.stack whenever it is not required.

Generated by OpenCVE AI on September 17, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) rather than a prototype-bypassing define-property primitive. Because this bridge-internal array is allocated in the sandbox realm, code inside the sandbox can install an accessor on Array.prototype for the relevant index; the accessor is then invoked whenever the sandbox reads error.stack (or otherwise triggers Error.prepareStackTrace), allowing sandbox code to observe and intercept each stack-trace line written by the bridge. The same pattern is used in the error-handling (catch) branch. The values written are formatted strings only, so the practical impact is limited to an information side channel and a violation of vm2's bridge-container defense invariant rather than a sandbox escape; the vendor rates the issue Low. The issue is fixed in vm2 3.11.4, which installs each entry as an own data property via Reflect.defineProperty.
Title vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:40:44.491Z

Reserved: 2026-09-17T12:43:31.527Z

Link: CVE-2026-92962

cve-icon Vulnrichment

Updated: 2026-09-17T15:40:41.331Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:02.610

Modified: 2026-09-17T16:18:34.940

Link: CVE-2026-92962

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-17T13:46:18Z

Links: CVE-2026-92962 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes