Protection mechanism failure in vm2 - #VU146042

 

Protection mechanism failure in vm2 - #VU146042

Published: August 28, 2026


Vulnerability identifier: #VU146042
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the host system and disclose sensitive information.

The vulnerability exists due to a protection mechanism failure in handleException error sanitization for AggregateError in vm2 when processing a host-wrapped AggregateError that is revisited within a single exception-handling traversal. A remote attacker can trigger a crafted host exception through an exposed host function to execute arbitrary code on the host system and disclose sensitive information.

The issue occurs on the caught-exception throw channel and is limited to AggregateError-based cyclic or duplicate reference shapes such as self-cycles, mutual-cycles, or the same host aggregate referenced multiple times in errors[].


Affected software

vm2

Remediation

Install security update from vendor's website.

vm2 - update to 3.11.8

External References

Related Security Bulletins