CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-47141

PENDING
N/A
CVSS Severity Score
EPSS Score0.1480%
EPSS Percentile17.50th
Published2026年6月12日
Last Modified2026年6月13日

Vulnerability Description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The diagnostics_channel, async_hooks, and perf_hooks builtins are not blocked by the dangerous builtin denylist. These modules are process-wide, not sandbox-local. Sandboxed code can use them to observe host application data across the vm2 boundary. This issue has been patched in version 3.11.4.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁