CVE-2026-92949

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-471

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve

    🟠 vm2, Sandbox Bypass via Accessor Descriptor, #CVE-2026-92949 (Medium) -DC-Oct2026-2699 https://dailycve.com/vm2-sandbox-bypass-via-accessor-descriptor-cve-2026-92949-medium-dc-oct2026-2699/

    0000020
    238 followersView on X

Explore more