{"id":"GHSA-x6m4-chr9-cg97","summary":"vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting","details":"## Summary\n\nAttacker-controlled code can trigger a host-realm syntax error and read its stack through the vm2 bridge. Host-realm stack formatting bypasses the sandbox-side redaction, so the returned value exposes absolute paths from vm2, Node.js internals, and the embedding application. Default VM and NodeVM configurations are affected without requiring special options.\n\n## PoC\n\nA default-configured `VM` runs attacker-supplied code. Calling `eval` with deliberately malformed source makes the host-side source transformer throw a `SyntaxError`; reading `.stack` on the caught error exposes the host call stack to the sandbox.\n\n```js\nconst { VM } = require(\"vm2\");\nconsole.log(new VM().run(`\n  var s; try { eval(\"@@@ catch\") } catch (e) { s = e.stack }\n  s;\n`));\n```\n\n### Observed output\n\n```text\nSyntaxError: Unexpected character '@'\n    at makeNiceSyntaxError (.../lib/transformer.js:41:16)\n    at transformer (.../lib/transformer.js:116:8)\n    at Object.transformAndCheck (.../lib/vm.js:76:14)\n    at Object.apply (.../lib/setup-sandbox.js:2585:16)\n    at VM.run (.../lib/vm.js:529:16)\n```\n\nThe stack string returned to the sandbox contains absolute host paths for `lib/transformer.js`, `lib/vm.js`, `lib/setup-sandbox.js`, Node internals, and the embedding application's own source file.\n\n## Impact\n\nSandboxed code running under the default `new VM()` or `new NodeVM()` configuration can read absolute filesystem paths of the embedding application's source tree plus host function names, bypassing the host-path redaction added for GHSA-v27g-jcqj-v8rw. On a multi-tenant code-runner this discloses deployment layout such as `/home/app/...` or `/var/task/...`, useful for fingerprinting and for chaining into further attacks. The bridge forwards `.stack` reads to the host-realm formatter (`lib/bridge.js:1482`), so the sandbox-side stack redaction never runs; the leak does not require special configuration and persists when string eval is disabled, because the host-side transformer throws before eval is handled. Information disclosure only, no code execution.","aliases":["CVE-2026-92936"],"modified":"2026-10-05T22:45:06.434355748Z","published":"2026-10-05T22:35:31Z","database_specific":{"github_reviewed_at":"2026-10-05T22:35:31Z","nvd_published_at":null,"cwe_ids":["CWE-209","CWE-497"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-x6m4-chr9-cg97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92936"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/5d5ba5343af571c688a3a81cefad2de25b94180a"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-3.11.0-before-3.11.7-information-disclosure-via-error-stack"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.11.0"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-x6m4-chr9-cg97/GHSA-x6m4-chr9-cg97.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}]}