CVE-2026-92952
## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code. The prior `nodejs.*` symbol hardening blocks `Symbol.for('nodejs.<name>')` at the source, but the extraction filters and bridge write traps still enumerate a fixed set of known registered symbols. On Node.js `v25.8.0`, `stream/web` exposes two additional registered symbols: - `nodejs.stream.disturbed` - `nodejs.stream.errored` Sandbox code can extract those real host symbols with `Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype)` and then use them as write keys on host objects. On a real host `ReadableStream`, an attacker can make `stream.Readable.isDisturbed(stream)` return `false` after the stream has already been read. ## Technical Details `lib/setup-sandbox.js` correctly blocks future `nodejs.*` keys at the `Symbol.for()` source: ```js if (apply(localStringStartsWith, keyStr, ['nodejs.'])) { ... return fresh; } ``` However, the extraction filters are still driven by a fixed `realDangerousSymbols` list. That list does not include `nodejs.stream.disturbed` or `nodejs.stream.errored`, so `Object.getOwnPropertySymbols()` and related paths can still return those real host symbols. `lib/bridge.js` has the same fixed-list problem in `isDangerousCrossRealmSymbol()` and in the host-result scrub list. Because the two new symbols are not recognized, the `set` and `defineProperty` traps allow sandbox-originated writes using those keys. Current-head source references: - `lib/setup-sandbox.js:180-196` denies `Symbol.for('nodejs.*')` by namespace. - `lib/setup-sandbox.js:214-230` uses a fixed `realDangerousSymbols` list for extraction filtering; the two reported symbols are absent. - `lib/bridge.js:187-199` uses a fixed `isDangerousCrossRealmSymbol()` list; the two reported symbols are absent. - `lib/bridge.js:1499-1509` treats the write trap as the last line o
Properties
- severity
- medium
- summary
- vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
- cvss_score
- 6.8
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:42:15Z
- source_url
- https://github.com/advisories/GHSA-jf8q-945g-9q4c
- ghsa_updated
- 2026-10-01T15:42:17Z
- ghsa_id
- GHSA-jf8q-945g-9q4c
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92952
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph