Disclosure summary
## Summary It being possible to obtain the host `__proto__` getter/setter, has been used in many reports: - https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq - https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg - https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p - https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6 Yet it was never patched... --- This can, still, be used to escape the sandbox, one example (I'm sure there's other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: 'inherit'`, which is the default) ## Details The prototype chain for `console._stdout`/`console._stderr` is: ``` _stdout / _stderr -> WriteStream (TTY only) -> Socket -> Duplex -> Readable -> Stream -> EventEmitter ``` `process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype` By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`. This also bypasses `--disallow-code-generation-from-strings`, which blocks the
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-88hf-g992-jg85
Open original source · Updated Oct 05, 2026
vm2: Sandbox Escape (NodeVM)
Source severity: CRITICAL / 10
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | vm2 | 3.11.8 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T18:47:09-04:00
MODIFIED 2026-10-05T18:47:10-04:00
INGESTED 2026-10-06T11:45:33-04:00