GHSA-xq74-c7jx-8w5j

Suggest an improvement
Source
https://github.com/advisories/GHSA-xq74-c7jx-8w5j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-xq74-c7jx-8w5j/GHSA-xq74-c7jx-8w5j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xq74-c7jx-8w5j
Withdrawn
2026-10-01T15:27:12Z
Published
2026-09-17T15:32:15Z
Modified
2026-10-01T15:45:05Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-98xx-8mx4-x7cm. This link is maintained to preserve external references.

Original Description

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

Database specific
{
    "cwe_ids": [
        "CWE-732"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:27:12Z",
    "nvd_published_at": "2026-09-17T14:17:59Z",
    "severity": "CRITICAL"
}
References

Affected packages

npm / vm2

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.11.3
Last Affected
3.11.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-xq74-c7jx-8w5j/GHSA-xq74-c7jx-8w5j.json"