CVE 8.6 HIGH

vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain_CVE-2026-47209

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inherits from the proxy via Object.create), the property assignment should create an own property on the receiver, not on the proxy target. The current implementation always calls otherReflectSet(object, key, value) against the host target, causing all inherited property writes to leak through to the host object. This bug provides an alternative attack vector for writing dangerous cross-realm Symbol keys (e.g., nodejs.util.promisify.custom) to host objects, bypassing any future per-trap isDangerousCrossRealmSymbol guard on the direct set path. This issue has been patched in version 3.11.4.

AI Analysis

Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain

Basic Information

ID CVE-2026-47209
Source GitHub_M
Published Jun 12, 2026 at 14:14
Modified Jun 12, 2026 at 15:03

Affected Product

Vendor patriksimek
Product vm2
Version < 3.11.4
Affected Versions patriksimek vm2 < 3.11.4

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor patriksimek
Product vm2
Version < 3.11.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.