VM2 Sandbox Bypass: Incomplete nodejs.* Symbol Filter Allows WebStream State Tampering (GHSA-jf8q-945g-9q4c)
Security Advisory
GHSA-jf8q-945g-9q4c
Medium
patriksimek/vm2
Affected:
- vm2 >= 3.11.4 <= 3.11.6
Fixed in:
- 3.11.7
Referenced CVEs:
CVE-2026-92952 · 6.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.