{"id":"CVE-2026-47141","aliases":["GHSA-9g8x-92q2-p28f"],"url":"https://o3.security/vulnerability/CVE-2026-47141","summary":"vm2: NodeVM observability builtins leak host process and HTTP request data","details":"vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The diagnostics_channel, async_hooks, and perf_hooks builtins are not blocked by the dangerous builtin denylist. These modules are process-wide, not sandbox-local. Sandboxed code can use them to observe host application data across the vm2 boundary. This issue has been patched in version 3.11.4.","published":"2026-06-12T14:17:35.970Z","modified":"2026-08-12T03:51:43.958379797Z","cvss":null,"epss":{"score":0.00308,"percentile":0.22888,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vm2","fixedVersion":"3.11.4"}],"fix":{"url":"https://github.com/patriksimek/vm2/commit/e1c48fce05189f48e71efbd32af0754efa4066bb","label":"patriksimek/vm2@e1c48fc"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47141.json"},{"type":"ADVISORY","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-9g8x-92q2-p28f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47141"},{"type":"FIX","url":"https://github.com/patriksimek/vm2/commit/e1c48fce05189f48e71efbd32af0754efa4066bb"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.958379797Z"}}