GHSA-2vh9-cv26-p97m

Suggest an improvement
Source
https://github.com/advisories/GHSA-2vh9-cv26-p97m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2vh9-cv26-p97m/GHSA-2vh9-cv26-p97m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2vh9-cv26-p97m
Withdrawn
2026-10-05T22:37:25Z
Published
2026-09-17T15:32:14Z
Modified
2026-10-05T22:45:04Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-r273-hxvj-fxhp. This link is maintained to preserve external references.

Original Description

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host util module to the sandbox as an unfiltered shallow copy (Object.assign({}, util) in defaultBuiltinLoaderUtil), and the deprecated sys builtin (an alias of host util) is exposed through the generic builtin loader. On Node.js >= 22.9 this hands sandboxed code util.getCallSites(), a programmatic stack-introspection API that returns the host process's full call stack, including absolute file paths, function names, and line numbers for vm2 bridge internals and the embedding application's entrypoint. This bypasses the host-frame redaction introduced for GHSA-v27g-jcqj-v8rw, which only applies to the Error.prepareStackTrace formatting channel. The issue is fixed in vm2 3.11.8.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T22:37:25Z",
    "nvd_published_at": "2026-09-17T14:17:57Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.11.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2vh9-cv26-p97m/GHSA-2vh9-cv26-p97m.json"