Impact
vm2 versions before 3.11.2 allow attackers to read the global variable VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL through globalThis, exposing sensitive sandbox internals such as configuration, memory, and potentially secrets. This is an information‑disclosure weakness identified as CWE‑227.
Affected Systems
The vulnerability affects the patriksimek:vm2 package, versions prior to 3.11.2.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the vulnerability is listed in CISA KEV as not present. Because the exploit relies on accessing a global variable within Node.js, it requires that untrusted code is executed inside a vm2 sandbox that exposes globalThis. No external exploitation vector is documented, but an attacker who can run code in that context can retrieve internal state information.
OpenCVE Enrichment