GHSA-538q-xxpg-6h4r

Suggest an improvement
Source
https://github.com/advisories/GHSA-538q-xxpg-6h4r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-538q-xxpg-6h4r/GHSA-538q-xxpg-6h4r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-538q-xxpg-6h4r
Withdrawn
2026-10-05T22:34:14Z
Published
2026-09-17T15:32:16Z
Modified
2026-10-05T22:45:05Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-wjwh-qqvp-g4p4. This link is maintained to preserve external references.

Original Description

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default new VM() sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host process object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.

Database specific
{
    "cwe_ids":  [
        "CWE-693"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:34:14Z",
    "nvd_published_at":  "2026-09-17T14:18:01Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.10.1
Last Affected
3.11.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-538q-xxpg-6h4r/GHSA-538q-xxpg-6h4r.json"