Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rp36-8xq3-r6c4 | NodeVM builtin denylist bypass via process and inspector/promises allows host code execution |
Tue, 16 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 12 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Patriksimek
Patriksimek vm2 |
|
| Vendors & Products |
Patriksimek
Patriksimek vm2 |
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. This issue has been patched in version 3.11.4. | |
| Title | vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-13T03:55:57.896Z
Reserved: 2026-05-18T19:50:18.696Z
Link: CVE-2026-47140
Updated: 2026-06-12T16:39:00.826Z
Status : Deferred
Published: 2026-06-12T15:16:28.400
Modified: 2026-06-12T17:16:23.830
Link: CVE-2026-47140
OpenCVE Enrichment
Updated: 2026-06-17T23:30:04Z
Github GHSA