Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cfcw-xp6x-25gj | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators |
Mon, 17 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6. | |
| Title | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators | |
| Weaknesses | CWE-913 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T20:53:09.218Z
Reserved: 2026-05-19T21:18:20.404Z
Link: CVE-2026-47698
No data.
Status : Received
Published: 2026-08-17T21:16:45.640
Modified: 2026-08-17T21:16:45.640
Link: CVE-2026-47698
No data.
OpenCVE Enrichment
No data.
Github GHSA