CVE-2026-92936
## Summary Attacker-controlled code can trigger a host-realm syntax error and read its stack through the vm2 bridge. Host-realm stack formatting bypasses the sandbox-side redaction, so the returned value exposes absolute paths from vm2, Node.js internals, and the embedding application. Default VM and NodeVM configurations are affected without requiring special options. ## PoC A default-configured `VM` runs attacker-supplied code. Calling `eval` with deliberately malformed source makes the host-side source transformer throw a `SyntaxError`; reading `.stack` on the caught error exposes the host call stack to the sandbox. ```js const { VM } = require("vm2"); console.log(new VM().run(` var s; try { eval("@@@ catch") } catch (e) { s = e.stack } s; `)); ``` ### Observed output ```text SyntaxError: Unexpected character '@' at makeNiceSyntaxError (.../lib/transformer.js:41:16) at transformer (.../lib/transformer.js:116:8) at Object.transformAndCheck (.../lib/vm.js:76:14) at Object.apply (.../lib/setup-sandbox.js:2585:16) at VM.run (.../lib/vm.js:529:16) ``` The stack string returned to the sandbox contains absolute host paths for `lib/transformer.js`, `lib/vm.js`, `lib/setup-sandbox.js`, Node internals, and the embedding application's own source file. ## Impact Sandboxed code running under the default `new VM()` or `new NodeVM()` configuration can read absolute filesystem paths of the embedding application's source tree plus host function names, bypassing the host-path redaction added for GHSA-v27g-jcqj-v8rw. On a multi-tenant code-runner this discloses deployment layout such as `/home/app/...` or `/var/task/...`, useful for fingerprinting and for chaining into further attacks. The bridge forwards `.stack` reads to the host-realm formatter (`lib/bridge.js:1482`), so the sandbox-side stack redaction never runs; the leak does not require special configuration and persists when string eval is disabled, because the host-side transformer throws b
Properties
- severity
- medium
- summary
- vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
- epss_score
- 0.00455
- cvss_score
- 5.8
- retrieved_at
- 2026-10-05T22:59:58+00:00
- ghsa_published
- 2026-10-05T22:35:31Z
- source_url
- https://github.com/advisories/GHSA-x6m4-chr9-cg97
- ghsa_updated
- 2026-10-05T22:35:34Z
- ghsa_id
- GHSA-x6m4-chr9-cg97
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-92936
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- signal_observed_at
- 2026-10-05T22:52:21+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.37287
Related Entities (6)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph