mediumCVSS 6.8Vulnerability

CVE-2026-92952

## Summary vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code. The prior `nodejs.*` symbol hardening blocks `Symbol.for('nodejs.<name>')` at the source, but the extraction filters and bridge write traps still enumerate a fixed set of known registered symbols. On Node.js `v25.8.0`, `stream/web` exposes two additional registered symbols: - `nodejs.stream.disturbed` - `nodejs.stream.errored` Sandbox code can extract those real host symbols with `Object.getOwnPropertySymbols(streamWeb.ReadableStream.prototype)` and then use them as write keys on host objects. On a real host `ReadableStream`, an attacker can make `stream.Readable.isDisturbed(stream)` return `false` after the stream has already been read. ## Technical Details `lib/setup-sandbox.js` correctly blocks future `nodejs.*` keys at the `Symbol.for()` source: ```js if (apply(localStringStartsWith, keyStr, ['nodejs.'])) { ... return fresh; } ``` However, the extraction filters are still driven by a fixed `realDangerousSymbols` list. That list does not include `nodejs.stream.disturbed` or `nodejs.stream.errored`, so `Object.getOwnPropertySymbols()` and related paths can still return those real host symbols. `lib/bridge.js` has the same fixed-list problem in `isDangerousCrossRealmSymbol()` and in the host-result scrub list. Because the two new symbols are not recognized, the `set` and `defineProperty` traps allow sandbox-originated writes using those keys. Current-head source references: - `lib/setup-sandbox.js:180-196` denies `Symbol.for('nodejs.*')` by namespace. - `lib/setup-sandbox.js:214-230` uses a fixed `realDangerousSymbols` list for extraction filtering; the two reported symbols are absent. - `lib/bridge.js:187-199` uses a fixed `isDangerousCrossRealmSymbol()` list; the two reported symbols are absent. - `lib/bridge.js:1499-1509` treats the write trap as the last line o

Properties

severity
medium
summary
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
cvss_score
6.8
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:42:15Z
source_url
https://github.com/advisories/GHSA-jf8q-945g-9q4c
ghsa_updated
2026-10-01T15:42:17Z
ghsa_id
GHSA-jf8q-945g-9q4c
last_source
GitHub Advisory Database
cve_id
CVE-2026-92952
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Incorrect Resource Transfer Between Spheres

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92952 (CVSS 6.8) — Ninja Signal Threat Intelligence | Ninja Signal