CVE-2026-92952: Incorrect Resource Transfer Between Spheres in patriksimek vm2
CVE-2026-92952 affects vm2 versions 3.11.4 through 3.11.6 and involves incomplete filtering of Node.js internal symbols across the sandbox boundary. This allows sandboxed code to access and manipulate host WebStream prototype symbols, potentially corrupting host stream state. The vulnerability can bypass host logic that relies on Node.js stream-state helpers, affecting enforcement of one-shot body consumption and error handling. It does not enable direct host code execution. The issue is fixed in vm2 version 3.11.7.
AI Analysis
Technical Summary
vm2 versions 3.11.4 through 3.11.6 fail to fully filter Node.js registered internal symbols across the sandbox boundary. The filtering mechanisms in lib/setup-sandbox.js and lib/bridge.js omit certain symbols (nodejs.stream.disturbed and nodejs.stream.errored) present on newer Node.js releases such as v25.8.0. When a host WebStream object and the host stream/web module are exposed to the sandbox, sandbox code can retrieve these real host symbols via Object.getOwnPropertySymbols and use them as write keys on host stream objects. This corrupts host-visible stream state, for example causing stream.Readable.isDisturbed() to incorrectly return false for an already-consumed stream. This bypasses host logic that depends on Node's public stream-state helpers to enforce stream consumption rules and error handling. The vulnerability does not directly allow host code execution. This is an incomplete fix of a previous symbol filtering issue and is resolved in vm2 3.11.7.
Potential Impact
The vulnerability allows sandboxed code to corrupt host stream state by manipulating internal Node.js stream symbols that were not filtered. This can bypass host logic enforcing one-shot body consumption, error rejection, and stream safety checks. Although it does not enable direct host code execution, it undermines the integrity of stream handling in the host environment, potentially leading to unexpected behavior or security bypasses in applications relying on these stream-state helpers.
Mitigation Recommendations
Upgrade vm2 to version 3.11.7 or later, where this issue is fixed. Versions 3.11.4 through 3.11.6 are affected. No other mitigations are indicated by the vendor advisory.
CVE-2026-92952: Incorrect Resource Transfer Between Spheres in patriksimek vm2
Description
CVE-2026-92952 affects vm2 versions 3.11.4 through 3.11.6 and involves incomplete filtering of Node.js internal symbols across the sandbox boundary. This allows sandboxed code to access and manipulate host WebStream prototype symbols, potentially corrupting host stream state. The vulnerability can bypass host logic that relies on Node.js stream-state helpers, affecting enforcement of one-shot body consumption and error handling. It does not enable direct host code execution. The issue is fixed in vm2 version 3.11.7.
CVSS v4.0
Score 8.9high
Affected software
patriksimek
vm2
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
vm2 versions 3.11.4 through 3.11.6 fail to fully filter Node.js registered internal symbols across the sandbox boundary. The filtering mechanisms in lib/setup-sandbox.js and lib/bridge.js omit certain symbols (nodejs.stream.disturbed and nodejs.stream.errored) present on newer Node.js releases such as v25.8.0. When a host WebStream object and the host stream/web module are exposed to the sandbox, sandbox code can retrieve these real host symbols via Object.getOwnPropertySymbols and use them as write keys on host stream objects. This corrupts host-visible stream state, for example causing stream.Readable.isDisturbed() to incorrectly return false for an already-consumed stream. This bypasses host logic that depends on Node's public stream-state helpers to enforce stream consumption rules and error handling. The vulnerability does not directly allow host code execution. This is an incomplete fix of a previous symbol filtering issue and is resolved in vm2 3.11.7.
Potential Impact
The vulnerability allows sandboxed code to corrupt host stream state by manipulating internal Node.js stream symbols that were not filtered. This can bypass host logic enforcing one-shot body consumption, error rejection, and stream safety checks. Although it does not enable direct host code execution, it undermines the integrity of stream handling in the host environment, potentially leading to unexpected behavior or security bypasses in applications relying on these stream-state helpers.
Mitigation Recommendations
Upgrade vm2 to version 3.11.7 or later, where this issue is fixed. Versions 3.11.4 through 3.11.6 are affected. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T12:43:03.568Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac65c155bf5e2cf5fdf666
Added to database: 09/17/2026, 22:12:17 UTC
Last enriched: 09/17/2026, 22:15:45 UTC
Last updated: 09/18/2026, 03:45:17 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.