Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47135

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — verified with a full util.promisify hijack chain. This issue has been patched in version 3.11.4.

A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. An attacker within the sandbox could exploit incomplete symbol interception and missing security checks to gain control over the host system. This could allow the attacker to execute arbitrary code outside the sandbox environment, leading to a complete compromise of the host.

Отчет

This vulnerability has been rated as Moderate for Red Hat Developer Hub and Red Hat Ansible Automation Platform. The vm2 sandbox exists as a transitive dependency in Red Hat Developer Hub and is only utilized during build time. The sandbox is therefore not exposed on the production code path. Exploitation of this vulnerability requires attackers to write cross-realm symbol keys to host objects which is not possible in the default configuration of Red Hat Developer Hub.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Red Hat Developer Hub 1.10rhdh/rhdh-hub-rhel9FixedRHSA-2026:3675408.07.2026
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:3357430.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1100
https://bugzilla.redhat.com/show_bug.cgi?id=2488396vm2: vm2: Sandbox escape allows arbitrary code execution on the host system

EPSS

Процентиль: 18%
0.00266
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
около 2 месяцев назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — verified with a full util.promisify hijack chain. This issue has been patched in version 3.11.4.

CVSS3: 8.7
github
2 месяца назад

vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks

EPSS

Процентиль: 18%
0.00266
Низкий

8.7 High

CVSS3