Improper access control in vm2 - #VU129598
Published: May 4, 2026
vm2
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the vm2 sandbox internal state handling when executing untrusted code. A remote attacker can access the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL object to disclose sensitive information.
The issue exposes an internal state object from within the sandbox.