Improper Access Control in VM2 Released by Patrik Simek
CVE-2026-92963
6.9MEDIUM
What is CVE-2026-92963?
The vm2 library, utilized for creating Node.js sandboxes, contains a vulnerability where versions prior to 3.11.2 fail to properly secure the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. This oversight allows unauthorized access to sensitive internal states through the globalThis object, potentially enabling attackers to extract confidential sandbox information. It is crucial for users of affected versions to promptly update to safeguard against this issue.
Affected Version(s)
vm2 0 < 3.11.2
vm2 3.11.2
