Improper Access Control in VM2 Released by Patrik Simek
CVE-2026-92963

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92963?

The vm2 library, utilized for creating Node.js sandboxes, contains a vulnerability where versions prior to 3.11.2 fail to properly secure the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. This oversight allows unauthorized access to sensitive internal states through the globalThis object, potentially enabling attackers to extract confidential sandbox information. It is crucial for users of affected versions to promptly update to safeguard against this issue.

Affected Version(s)

vm2 0 < 3.11.2

vm2 3.11.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

XmiliaH
.