Description
vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via unprotected internal state
Action: Immediate Patch
AI Analysis

Impact

vm2 versions before 3.11.2 allow attackers to read the global variable VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL through globalThis, exposing sensitive sandbox internals such as configuration, memory, and potentially secrets. This is an information‑disclosure weakness identified as CWE‑227.

Affected Systems

The vulnerability affects the patriksimek:vm2 package, versions prior to 3.11.2.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the vulnerability is listed in CISA KEV as not present. Because the exploit relies on accessing a global variable within Node.js, it requires that untrusted code is executed inside a vm2 sandbox that exposes globalThis. No external exploitation vector is documented, but an attacker who can run code in that context can retrieve internal state information.

Generated by OpenCVE AI on September 18, 2026 at 00:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.2 or later.
  • Ensure that code executing inside the sandbox does not access globalThis or expose the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL variable. If upgrading is not possible, remove or shadow the internal state object to prevent disclosure.
  • If upgrading is not feasible, patch the library to delete or rename VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL before sandbox initialization to block disclosure.

Generated by OpenCVE AI on September 18, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-767
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.
Title vm2 before 3.11.2 Information Disclosure via Internal State
Weaknesses CWE-227
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:15:28.242Z

Reserved: 2026-09-17T12:43:31.528Z

Link: CVE-2026-92963

cve-icon Vulnrichment

Updated: 2026-09-18T19:15:06.338Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:02.783

Modified: 2026-09-18T20:17:31.370

Link: CVE-2026-92963

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T13:46:18Z

Links: CVE-2026-92963 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-227
  • CWE-767

    Access to Critical Private Variable via Public Method