Junglewise Threat Intelligence

CVE-2026-92949: vm2 sandbox bypass via accessor descriptor on frozen objects

CVE-2026-92949 · Severity: medium · CVSS 4 · Published 2026-09-17

Technologies: Patriksimek Vm2.

Executive brief

vm2 is a Node.js sandboxing library that allows developers to safely execute untrusted JavaScript code in an isolated environment. A vulnerability in versions 3.9.6–3.11.6 allows malicious scripts to bypass the vm.freeze() and vm.readonly() protections—which are meant to prevent modification of critical host objects—by accessing and directly invoking accessor properties (getters/setters) to mutate read-only data. Depending on what host objects are exposed, this could enable attackers to manipulate application state or, in some cases, escalate to host code execution.

Technical details

The vulnerability is a protection mechanism failure (CWE-693) affecting the ReadOnlyHandler proxy in vm2's sandbox implementation. When an embedder freezes a host object containing accessor own-properties using vm.freeze() or vm.readonly(), the proxy fails to intercept calls to Object.getOwnPropertyDescriptor() or __lookupSetter__(), which allow sandboxed code to extract the underlying setter function and invoke it directly via .call(). The setter then executes against the unwrapped raw host object in BaseHandler.apply, bypassing the readonly proxy layer. No special VM options or authentication is required; the only precondition is that the embedder has frozen an object with at least one accessor property. Patch version 3.11.7 and later properly restrict access to accessor descriptors.

Affected products

  • patriksimek vm2 3.9.6 through 3.11.6

Timeline

  • 2026-08-24: disclosed: GitHub Security Advisory GHSA-633r-hq9m-c4ff published
  • 2026-08-24: patched: Patch version 3.11.7 released
  • 2026-09-17: advisory: CVE-2026-92949 assigned

References