Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-92963

Опубликовано: 17 сент. 2026
Источник: redhat
CVSS3: 5.3

Описание

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.

A flaw was found in vm2. An attacker can exploit this vulnerability by improperly accessing the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable through globalThis. This allows the attacker to retrieve sensitive internal information from the sandbox environment, leading to information disclosure.

Отчет

This Moderate impact information disclosure vulnerability in vm2 allows attackers to access sensitive sandbox internals. However, Red Hat products are not affected by this flaw as the vulnerable code is not present in Red Hat's supported offerings.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backendNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backendNot affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalNot affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-767
https://bugzilla.redhat.com/show_bug.cgi?id=2536030vm2: vm2: Sensitive information disclosure due to internal state access

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
6 дней назад

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.

CVSS3: 5.3
github
6 дней назад

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.

5.3 Medium

CVSS3