vm2 在 3.12.2 版本之前,在 NodeVM 的外部模块解析器中存在授权绕过漏洞。当嵌入方(embedder)通过 配置并使用自定义解析器设置 时, 中的 会将解析后的模块目录以 的形式记录在 中,但未要求路径分隔符或字符串结尾边界。 因此,不受信任的访客代码可以首先请求允许列表中的模块(例如 ),然后请求其非允许列表兄弟模块的绝对路径,而该兄弟模块的路径仅需共享已解析的前缀即可(例如 )。由于该兄弟模块路径通过了 检查,它将通过 被加载,从而在 包装其导出之前,在宿主进程中执行其顶层代码。这会导致沙箱逃逸
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| patriksimek | vm2 | 0 ~ 3.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100723 | 7.5 HIGH | vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool |
| CVE-2026-100722 | 6.8 MEDIUM | vm2 before 3.12.2 Host Process Termination via Construct Trap |
No comments yet