Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-44002

3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-44002

3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-v27g-jcqj-v8rw

3 месяца назад

vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2026-06966

3 месяца назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-44002

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.

CVSS3: 5.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44002

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0.

CVSS3: 5.8
0%
Низкий
3 месяца назад
github логотип
GHSA-v27g-jcqj-v8rw

vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak

CVSS3: 5.8
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-06966

Уязвимость библиотеки vm2 пакетного менеджера NPM, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу