Protection Mechanism Failure in vm2 - #VU131733
Published: May 18, 2026
vm2
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to protection mechanism failure in NodeVM builtin module restrictions when resolving excluded network builtins. A remote attacker can require internal modules such as _http_client and _http_server to disclose sensitive information.
This can provide SSRF-style access to localhost services, metadata endpoints, internal admin panels, or other network resources reachable from the host process.