mediumCVSS 5.8Vulnerability

CVE-2026-92936

## Summary Attacker-controlled code can trigger a host-realm syntax error and read its stack through the vm2 bridge. Host-realm stack formatting bypasses the sandbox-side redaction, so the returned value exposes absolute paths from vm2, Node.js internals, and the embedding application. Default VM and NodeVM configurations are affected without requiring special options. ## PoC A default-configured `VM` runs attacker-supplied code. Calling `eval` with deliberately malformed source makes the host-side source transformer throw a `SyntaxError`; reading `.stack` on the caught error exposes the host call stack to the sandbox. ```js const { VM } = require("vm2"); console.log(new VM().run(` var s; try { eval("@@@ catch") } catch (e) { s = e.stack } s; `)); ``` ### Observed output ```text SyntaxError: Unexpected character '@' at makeNiceSyntaxError (.../lib/transformer.js:41:16) at transformer (.../lib/transformer.js:116:8) at Object.transformAndCheck (.../lib/vm.js:76:14) at Object.apply (.../lib/setup-sandbox.js:2585:16) at VM.run (.../lib/vm.js:529:16) ``` The stack string returned to the sandbox contains absolute host paths for `lib/transformer.js`, `lib/vm.js`, `lib/setup-sandbox.js`, Node internals, and the embedding application's own source file. ## Impact Sandboxed code running under the default `new VM()` or `new NodeVM()` configuration can read absolute filesystem paths of the embedding application's source tree plus host function names, bypassing the host-path redaction added for GHSA-v27g-jcqj-v8rw. On a multi-tenant code-runner this discloses deployment layout such as `/home/app/...` or `/var/task/...`, useful for fingerprinting and for chaining into further attacks. The bridge forwards `.stack` reads to the host-realm formatter (`lib/bridge.js:1482`), so the sandbox-side stack redaction never runs; the leak does not require special configuration and persists when string eval is disabled, because the host-side transformer throws b

Properties

severity
medium
summary
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
epss_score
0.00455
cvss_score
5.8
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:35:31Z
source_url
https://github.com/advisories/GHSA-x6m4-chr9-cg97
ghsa_updated
2026-10-05T22:35:34Z
ghsa_id
GHSA-x6m4-chr9-cg97
last_source
FIRST EPSS
cve_id
CVE-2026-92936
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.37287

Related Entities (6)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (2)

→[Weakness]Exposure of Sensitive System Information to an Unauthorized Control Sphere
→[Weakness]Generation of Error Message Containing Sensitive Information

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92936 (CVSS 5.8) — Ninja Signal Threat Intelligence | Ninja Signal