CVE-2026-92933: vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack
NodeVM exposes the host util module to the sandbox through an unfiltered shallow copy (Object.assign({}, util)). On Node.js >= 22.9 this hands sandboxed code util.getCallSites(), a programmatic stack-introspection API that returns the host process’s full call stack — absolute file paths, function names, and line numbers — including vm2 bridge internals and the embedding application’s entrypoint. This bypasses the host-frame redaction established in GHSA-v27g-jcqj-v8rw, which only covers the Error.prepareStackTrace channel.
References
- github.com/advisories/GHSA-r273-hxvj-fxhp
- github.com/patriksimek/vm2/commit/e10bd2f539ab1a90c2d37466e6aae740d4a1ce2a
- github.com/patriksimek/vm2/releases/tag/v3.11.8
- github.com/patriksimek/vm2/security/advisories/GHSA-r273-hxvj-fxhp
- nvd.nist.gov/vuln/detail/CVE-2026-92933
- www.vulncheck.com/advisories/vm2-before-3.11.8-information-disclosure-via-util-getcallsites
Code Behaviors & Features
Detect and mitigate CVE-2026-92933 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →