Information Exposure Through an Error Message in vm2 - CVE-2026-44002

 

Information Exposure Through an Error Message in vm2 - CVE-2026-44002

Published: May 4, 2026


Vulnerability identifier: #VU129587
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44002
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information about the host environment.

The vulnerability exists due to generation of error messages containing sensitive information in the CallSite wrapper class when processing stack traces from sandboxed code. A remote attacker can trigger an error or override Error.prepareStackTrace to disclose sensitive information about the host environment.

The issue exposes host absolute paths, source locations, and internal function names to sandboxed code.


Affected software

vm2

How to mitigate CVE-2026-44002

Install security update from vendor's website.

vm2 - update to 3.11.0

External References

Related Security Bulletins