Exposure of Resource to Wrong Sphere in vm2 - CVE-2026-47141

 

Exposure of Resource to Wrong Sphere in vm2 - CVE-2026-47141

Published: May 18, 2026


Vulnerability identifier: #VU131732
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47141
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to exposure of process-wide observability resources to the wrong sphere in NodeVM builtin module handling when allowing require.builtin access to diagnostics_channel, async_hooks, or perf_hooks. A remote user can run untrusted JavaScript that uses these builtins to disclose sensitive information.

Exploitation requires the host application to allow these builtins and use HTTP, async request context, diagnostics channels, or performance marks in the same process.


Affected software

vm2

How to mitigate CVE-2026-47141

Install security update from vendor's website.

vm2 - update to 3.11.4

External References

Related Security Bulletins