| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m283-3h24-438v | VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 19 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patriksimek
Patriksimek vm2 |
|
| Vendors & Products |
Patriksimek
Patriksimek vm2 |
Mon, 17 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws an error with that object as its cause and then execute arbitrary host commands. This issue is fixed in version 3.11.6. | |
| Title | vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-19T03:56:00.965Z
Reserved: 2026-05-19T21:18:20.403Z
Link: CVE-2026-47686
Updated: 2026-08-18T17:28:39.734Z
Status : Received
Published: 2026-08-17T21:16:45.507
Modified: 2026-08-19T04:17:21.177
Link: CVE-2026-47686
No data.
OpenCVE Enrichment
Updated: 2026-08-18T00:15:03Z
Github GHSA