| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rp36-8xq3-r6c4 | NodeVM builtin denylist bypass via process and inspector/promises allows host code execution |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patriksimek
Patriksimek vm2 |
|
| Vendors & Products |
Patriksimek
Patriksimek vm2 |
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. This issue has been patched in version 3.11.4. | |
| Title | vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T16:39:14.066Z
Reserved: 2026-05-18T19:50:18.696Z
Link: CVE-2026-47140
Updated: 2026-06-12T16:39:00.826Z
Status : Deferred
Published: 2026-06-12T15:16:28.400
Modified: 2026-06-12T17:16:23.830
Link: CVE-2026-47140
No data.
OpenCVE Enrichment
Updated: 2026-06-12T16:00:20Z
Github GHSA