Impact
The vulnerability lies in the vm2 library’s stack‑trace preparation routine, which incorrectly populates an array using prototype walking instead of securely defining properties. This flaw permits code inside a sandbox to install a custom accessor on Array.prototype for the specific index used while constructing a stack trace. When the sandbox code triggers Error.prepareStackTrace or accesses error.stack, the accessor fires and exposes each line of the stack trace to the sandbox environment. Consequently, an attacker can read internal call paths, creating an information side channel. According to the CWE classification, this weakness is identified as CWE‑693: Protection Mechanism Failure, and the vendor rates the issue’s severity as low.
Affected Systems
The issue affects the vm2 package from patriksimek, specifically all releases up to and including v3.11.3. The problem originates in lib/setup-sandbox.js and is eliminated in vm2 v3.11.4, where a proper own property definition is used for each stack‑trace entry.
Risk and Exploitability
With a CVSS score of 2.1, the vulnerability is considered low severity. No EPSS data is available, and the flaw is not present in the CISA KEV catalog. The side‑channel nature of the attack reduces the overall risk; an adversary would need to execute untrusted code in a sandbox and rely on stack‑trace access to harvest useful information. The lack of a known exploitation vector in the wild further limits immediate risk.
OpenCVE Enrichment