
🟠 vm2, Sandbox Bypass via Accessor Descriptor, #CVE-2026-92949 (Medium) -DC-Oct2026-2699 https://dailycve.com/vm2-sandbox-bypass-via-accessor-descriptor-cve-2026-92949-medium-dc-oct2026-2699/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 vm2, Sandbox Bypass via Accessor Descriptor, #CVE-2026-92949 (Medium) -DC-Oct2026-2699 https://dailycve.com/vm2-sandbox-bypass-via-accessor-descriptor-cve-2026-92949-medium-dc-oct2026-2699/