CVE Vulnerabilities

CVE-2026-92955

Improper Control of Dynamically-Managed Code Resources

Published: Sep 17, 2026 | Modified: Sep 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
10 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host proto getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697*
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282*

Potential Mitigations

References