CWE-693
DiscouragedProtection Mechanism Failure
Abstraction: Pillar · Status: Draft
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
1336 vulnerabilities reference this CWE, most recent first.
GHSA-23CX-VH2C-742X
Vulnerability from github – Published: 2022-05-14 03:15 – Updated: 2022-05-14 03:15The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.
{
"affected": [],
"aliases": [
"CVE-2018-9320"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-05-31T12:29:00Z",
"severity": "HIGH"
},
"details": "The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.",
"id": "GHSA-23cx-vh2c-742x",
"modified": "2022-05-14T03:15:27Z",
"published": "2022-05-14T03:15:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9320"
},
{
"type": "WEB",
"url": "https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf"
},
{
"type": "WEB",
"url": "https://www.theregister.co.uk/2018/05/23/bmw_security_bugs"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/104258"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-246M-JXXR-PRQR
Vulnerability from github – Published: 2026-07-22 21:32 – Updated: 2026-07-24 21:32BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
{
"affected": [],
"aliases": [
"CVE-2025-50325"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-22T21:17:11Z",
"severity": "MODERATE"
},
"details": "BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip",
"id": "GHSA-246m-jxxr-prqr",
"modified": "2026-07-24T21:32:21Z",
"published": "2026-07-22T21:32:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50325"
},
{
"type": "WEB",
"url": "https://en.bandisoft.com/bandizip/help/zone-identifier"
},
{
"type": "WEB",
"url": "https://en.bandisoft.com/bandizip/history"
},
{
"type": "WEB",
"url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50325.md"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-24X9-R6Q4-Q93W
Vulnerability from github – Published: 2026-05-21 21:25 – Updated: 2026-05-21 21:25Description
When the sandbox is enabled selectively via SourcePolicyInterface (and not globally), a sandboxed template that is allowed to call template_from_string and include can render an arbitrary inner template with no security policy enforcement.
Environment::createTemplate() compiles the inner string under a synthesized name (__string_template__<hash>), so a name/path-based SourcePolicy returns false for it, and the inner template's checkSecurity() becomes a no-op. From a template the integrator believes is sandboxed, an attacker can use any tag/filter/function (including constant() to read secrets, or |map("system") to execute shell commands).
Resolution
This is a configuration trap rather than a code bug: there is no legitimate use case for exposing template_from_string to untrusted template authors, and propagating the parent sandbox state through template_from_string would require invasive changes to SourcePolicyInterface semantics with their own risks.
Starting with Twig 3.26.0, the documentation and the PHPDoc of StringLoaderExtension::templateFromString() explicitly warn against allowing template_from_string in a sandboxed environment (i.e. listing it in a SecurityPolicy allowed-functions list). Integrators using a SourcePolicyInterface MUST NOT allow template_from_string in their allowed functions; the safest option is not to register StringLoaderExtension at all when a sandbox is in use.
Credits
Twig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "twig/twig"
},
"ranges": [
{
"events": [
{
"introduced": "3.9.0"
},
{
"fixed": "3.26.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-46634"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-21T21:25:12Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Description\n\nWhen the sandbox is enabled selectively via `SourcePolicyInterface` (and not globally), a sandboxed template that is allowed to call `template_from_string` and `include` can render an arbitrary inner template with no security policy enforcement.\n\n`Environment::createTemplate()` compiles the inner string under a synthesized name (`__string_template__\u003chash\u003e`), so a name/path-based `SourcePolicy` returns `false` for it, and the inner template\u0027s `checkSecurity()` becomes a no-op. From a template the integrator believes is sandboxed, an attacker can use any tag/filter/function (including `constant()` to read secrets, or `|map(\"system\")` to execute shell commands).\n\n### Resolution\n\nThis is a configuration trap rather than a code bug: there is no legitimate use case for exposing `template_from_string` to untrusted template authors, and propagating the parent sandbox state through `template_from_string` would require invasive changes to `SourcePolicyInterface` semantics with their own risks.\n\nStarting with Twig 3.26.0, the documentation and the PHPDoc of `StringLoaderExtension::templateFromString()` explicitly warn against allowing `template_from_string` in a sandboxed environment (i.e. listing it in a `SecurityPolicy` allowed-functions list). Integrators using a `SourcePolicyInterface` MUST NOT allow `template_from_string` in their allowed functions; the safest option is not to register `StringLoaderExtension` at all when a sandbox is in use.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue.",
"id": "GHSA-24x9-r6q4-q93w",
"modified": "2026-05-21T21:25:12Z",
"published": "2026-05-21T21:25:12Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/twigphp/Twig/security/advisories/GHSA-24x9-r6q4-q93w"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46634.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/twigphp/Twig"
},
{
"type": "WEB",
"url": "https://symfony.com/cve-2026-46634"
}
],
"schema_version": "1.4.0",
"severity": [],
"summary": "Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name"
}
GHSA-2587-W93G-63M2
Vulnerability from github – Published: 2022-02-16 00:01 – Updated: 2022-12-01 22:34Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
This allows attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
This vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the LTS upgrade guide.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 336.v182c0fbaaeb7"
},
"package": {
"ecosystem": "Maven",
"name": "com.datapipe.jenkins.plugins:hashicorp-vault-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "351.vdb_f83a_1c6a_9d"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-25197"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-01T22:34:55Z",
"nvd_published_at": "2022-02-15T17:15:00Z",
"severity": "MODERATE"
},
"details": "Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.\n\nThis allows attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.\n\nThis vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.303/#upgrading-to-jenkins-lts-2-303-3).",
"id": "GHSA-2587-w93g-63m2",
"modified": "2022-12-01T22:34:55Z",
"published": "2022-02-16T00:01:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25197"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/hashicorp-vault-plugin/commit/c564958154e5b2eccb2423b0aaabd01b928f71fc"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/hashicorp-vault-plugin"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/hashicorp-vault-plugin/releases/tag/351.vdb_f83a_1c6a_9d"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2521"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files"
}
GHSA-25JH-5H5R-H33M
Vulnerability from github – Published: 2022-05-17 04:32 – Updated: 2024-10-09 21:34gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "Plone"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.2.3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "Plone"
},
"ranges": [
{
"events": [
{
"introduced": "4.3a0"
},
{
"fixed": "4.3b1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2012-5493"
],
"database_specific": {
"cwe_ids": [
"CWE-693",
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2023-08-29T21:37:11Z",
"nvd_published_at": "2014-09-30T14:55:00Z",
"severity": "MODERATE"
},
"details": "`gtbn.py` in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.",
"id": "GHSA-25jh-5h5r-h33m",
"modified": "2024-10-09T21:34:03Z",
"published": "2022-05-17T04:32:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-5493"
},
{
"type": "PACKAGE",
"url": "https://github.com/plone/Plone"
},
{
"type": "WEB",
"url": "https://github.com/plone/Products.CMFPlone/blob/4.2.3/docs/CHANGES.txt"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-35.yaml"
},
{
"type": "WEB",
"url": "https://plone.org/products/plone-hotfix/releases/20121106"
},
{
"type": "WEB",
"url": "https://plone.org/products/plone/security/advisories/20121106/09"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/11/10/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H",
"type": "CVSS_V4"
}
],
"summary": "Plone Sandbox Bypass"
}
GHSA-2675-54P5-24WW
Vulnerability from github – Published: 2022-12-15 21:30 – Updated: 2022-12-20 03:30A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.
{
"affected": [],
"aliases": [
"CVE-2022-42821"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-15T19:15:00Z",
"severity": "MODERATE"
},
"details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.",
"id": "GHSA-2675-54p5-24ww",
"modified": "2022-12-20T03:30:28Z",
"published": "2022-12-15T21:30:29Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42821"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213488"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213533"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213534"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2022/Dec/24"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2022/Dec/25"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-27G9-P43V-CW3V
Vulnerability from github – Published: 2026-10-01 15:28 – Updated: 2026-10-01 15:28Reporter
- Name or handle:
[YMsora] - Report date: 2026-08-14
Summary
The latest published vm2 release, 3.11.5, and the current main branch are vulnerable to a sandbox escape when used on Node.js 26. An ordinary fulfilled Promise created by an async function can retain an attacker-controlled constructor[Symbol.species] across Promise.prototype.finally().
vm2 installs wrappers on the intrinsic Promise.prototype.then and catch methods. On Node.js 26 / V8 14.6, V8's SetPrototypeProperties path updates these existing data properties without invalidating the PromiseThenLookupChain protector. Promise.prototype.finally() subsequently trusts the stale protector and uses an internal InvokeThen fast path that calls the original native then, bypassing vm2's wrapper and its resetPromiseSpecies(this) hardening.
The attacker-controlled species constructor therefore supplies the resolve and reject functions used by a native Promise reaction. A calibrated stack overflow at that native reaction boundary yields a raw host-realm RangeError to the attacker-controlled reject function. Its constructor chain reaches the host Function constructor and consequently the host process object.
The attached proof is non-destructive: it reads only process.version. It does not execute commands, access files, or perform network requests.
Latest-version status
Verified on 2026-08-14:
- npm
latest:vm2@3.11.5 vm2@3.11.5publication time: 2026-05-18T15:37:26.138Z- npm
gitHead:7a1f5100b96f48d34e0fe104ab37c0acc5944f92 - npm tarball:
https://registry.npmjs.org/vm2/-/vm2-3.11.5.tgz - npm integrity:
sha512-RSrkBiwrj6FRU+QdqNs6KG0XdlvJCjpQ4GXiqmMbrhmwfu5k/XIMpAer0L8f6iuf0uJ3a4T1xJN126Q8yf0VIA== - GitHub default branch
mainHEAD: the same commit, also taggedv3.11.5 - latest formal Node.js release:
v26.7.0, V814.6.202.34
The npm tarball and current GitHub main contain the same relevant lib/setup-sandbox.js Git blob. There is no unpublished fix on main at the time of this report.
Permanent source reference:
Affected configurations
vm2 versions tested on Node.js 26.7.0
| vm2 version | Result |
|---|---|
| 3.10.2 through 3.10.5 | host realm reached, 3/3 per release |
| 3.11.0 | host realm reached, 3/3 |
| 3.11.1 | host realm reached, 3/3 |
| 3.11.2 | host realm reached, 5/5 |
| 3.11.3 | host realm reached, 3/3 |
| 3.11.4 | host realm reached, 5/5 |
| 3.11.5 | host realm reached, 5/5 |
current main (7a1f5100) |
host realm reached, 5/5 |
This report therefore confirms vm2 3.10.2 through 3.11.5 as affected when used with the vulnerable runtime. Earlier vm2 versions are not claimed: they may be independently vulnerable through older published issues, which would not establish this root cause.
Node.js versions tested with stock vm2 3.11.5
| Node.js | V8 | Result |
|---|---|---|
| 22.23.2 | 12.4.254.21 | safe, 5/5 |
| 24.19.0 | 13.6.233.17 | safe, 5/5 |
| 25.9.0 | 14.1.146.11 | safe, 5/5 |
| 26.0.0 | 14.6.202.33 | host realm reached, 5/5 |
| every formal release from 26.1.0 through 26.7.0 | 14.6.202.34 | host realm reached, 5/5 per release |
| v27.0.0-nightly202608131b2de5e052 | 14.6.202.34 | host realm reached |
| v27.0.0-v8-canary20260812f3fe529a1e | 15.3.55 | safe |
The vulnerable behavior was reproduced on Linux/musl, Linux/glibc, and Windows x64. It is not Alpine-specific.
Configuration requirements
The default configuration is affected:
const vm = new VM();
Default new VM() was verified 3/3 on Node.js 26.7.0 and vm2 3.11.5 with the operating system's default Node stack size.
The escape also remains reproducible with stronger settings:
const vm = new VM({
allowAsync: true,
eval: false,
wasm: false,
timeout: 5000
});
Therefore the exploit does not require:
- WebAssembly or JSPI;
- dynamic evaluation being enabled;
- Buffer;
- an exposed host object;
- a custom Promise supplied by the embedder;
- a specific operating system; or
- any challenge-specific code.
The demonstrated producer uses an async function, so async support must be available. This is vm2's default.
The V8 PromiseThenLookupChain protector must still be intact when vm2 installs its wrappers. A fresh/default Node.js process satisfies this condition. An unrelated earlier mutation that correctly invalidates the protector can make this exact path safe, but that is not a documented vm2 mitigation and is not present in the default setup.
Reproduction
The attachment poc.js uses only the published npm package and prints a benign host-version marker.
mkdir vm2-node26-repro
cd vm2-node26-repro
npm init -y
npm install --ignore-scripts --no-audit --no-fund vm2@3.11.5
cp /path/to/poc.js .
node poc.js
Alternatively, with the official Node.js 26.7.0 container:
docker run --rm -v "$PWD:/poc:ro" -w /tmp node:26.7.0-bookworm-slim sh -lc '
npm init -y >/dev/null 2>&1 &&
npm install --ignore-scripts --no-audit --no-fund vm2@3.11.5 >/dev/null 2>&1 &&
cp /poc/poc.js . &&
node poc.js
'
Representative output:
{
"node": "v26.7.0",
"v8": "14.6.202.34-node.28",
"vm2": "3.11.5",
"config": "default",
"result": "HOST",
"hostVersion": "v26.7.0",
"speciesCalls": 1,
"localError": false,
"localRangeError": false
}
The calibrated depth varies with the platform and process layout; this is expected. The PoC searches the boundary instead of relying on a fixed depth.
To verify that disabling eval and WebAssembly is not sufficient:
STRICT=1 node poc.js
Technical root cause
- vm2 replaces the intrinsic
Promise.prototype.thenandcatchmethods with wrappers that sanitize callbacks and executeresetPromiseSpecies(this). - These two prototype writes are consecutive direct assignments in
lib/setup-sandbox.js. - V8 14.6 enables the
proto_assign_seq_optoptimization, combining this assignment sequence intoSetPrototypeProperties. - In the Node.js 26 implementation, the existing-data-property branch calls
Object::SetDataProperty(&it, value)without first callingit.UpdateProtector(). - The JavaScript property now contains vm2's wrapper, but the V8
PromiseThenLookupChainprotector incorrectly remains valid. Promise.prototype.finally()performs an internalInvokeThen. Because the protector appears valid, V8 directly selects the native Promisetheninstead of performing the observable property lookup that would reach vm2's wrapper.- The wrapper never executes, so the attacker's own
constructor[Symbol.species]is not reset before the nativethencreates its result capability. - A native Promise reaction calls the attacker-provided capability resolve function. At a calibrated stack boundary, V8 creates a host-realm
RangeErrorand passes it to the attacker-provided capability reject function without vm2 conversion. error.constructor.constructoris consequently the hostFunction, even when the VM was configured witheval:false.
The root-cause control is strong:
node --no-proto-assign-seq-opt poc.js
On Node.js 26.7.0 this changes the result from HOST to SAFE (3/3). A separate semantic probe also changes from wrapperCalls=0 to wrapperCalls=1.
Relationship to previous advisories
This report intentionally discloses the overlap with prior work:
CVE-2026-22709 / GHSA-99p7-6v5w-7xg8
That issue concerned bypassing callback sanitization on intrinsic Promises returned by async functions. vm2's fix added/strengthened the globalPromise.prototype.then and catch wrappers. The current issue is different: on V8 14.6, finally() trusts a stale protector and bypasses those installed wrappers at the engine fast path.
CVE-2026-47208 / GHSA-76w7-j9cq-rx2j
That issue used a missing resetPromiseSpecies call in localPromise's rejection-swallowing tail. It is marked fixed in 3.11.4. The current entry point is the intrinsic async Promise plus finally()/InvokeThen; the PoC succeeds against 3.11.4 and 3.11.5.
CVE-2026-47210 / GHSA-6j2x-vhqr-qr7q
That issue required a JSPI-backed Promise and WebAssembly APIs. Its 3.11.4 fix removes the relevant JSPI surface. The current PoC uses an ordinary fulfilled async-function Promise, works with wasm:false, and succeeds against 3.11.5.
Public V8 fix
The underlying V8 protector bookkeeping bug is already public and fixed upstream:
- data-property branch: https://github.com/v8/v8/commit/7b26e81087ec88c287d9a4812f969d412f32774e
- follow-up lazy-accessor branch: https://github.com/v8/v8/commit/4635ddd85839461c8ad791990023a477efefe7bd
This report does not claim discovery of a new V8 bug. It reports a previously undocumented, still-unpatched vm2 sandbox escape created by the interaction between that V8 bug and vm2's Promise hardening. The escape affects vm2's latest release and current main branch.
Impact
An attacker who can execute untrusted JavaScript inside a vm2 VM can cross the sandbox boundary and obtain the host Function constructor and process object. This permits arbitrary code execution with the privileges of the host Node.js process, including access to its filesystem, credentials, environment, network, and child-process facilities.
This is the exact security boundary vm2 is intended to enforce; no additional application mistake is required beyond executing attacker-controlled code in the sandbox.
Suggested remediation
- Install the intrinsic
thenandcatchwrappers through an operation that reliably invalidates V8's Promise lookup-chain protector, such as an appropriateReflect.defineProperty/Object.definePropertypath, instead of the optimizable consecutive direct-assignment sequence. - Wrap the intrinsic
Promise.prototype.finallyentry point and executeresetPromiseSpecies(this)before delegating to the cached nativefinallyimplementation. - Add a build/runtime regression test using an intrinsic Promise from
(async () => 1)(): an attacker-controlled own species must not be constructed byp.finally(). - Until a vm2 release is available, document Node.js 26 as affected or fail closed on the vulnerable runtime range.
- Coordinate with Node.js to backport the existing V8 protector fixes to the Node.js 26 release line.
Verified controls show that wrapping finally before calling the cached native implementation blocks the tested direct variants, while the upstream V8 fix also restores correct wrapper invocation.
Credit is requested as: YMsora. https://github.com/YMs0ra
Attachments
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 3.11.6"
},
"package": {
"ecosystem": "npm",
"name": "vm2"
},
"ranges": [
{
"events": [
{
"introduced": "3.10.2"
},
{
"fixed": "3.11.7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-92944"
],
"database_specific": {
"cwe_ids": [
"CWE-693",
"CWE-913"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:28:07Z",
"nvd_published_at": null,
"severity": "CRITICAL"
},
"details": "## Reporter\n\n- Name or handle: `[YMsora]`\n- Report date: 2026-08-14\n\n## Summary\n\nThe latest published vm2 release, **3.11.5**, and the current `main` branch are vulnerable to a sandbox escape when used on Node.js 26. An ordinary fulfilled Promise created by an async function can retain an attacker-controlled `constructor[Symbol.species]` across `Promise.prototype.finally()`.\n\nvm2 installs wrappers on the intrinsic `Promise.prototype.then` and `catch` methods. On Node.js 26 / V8 14.6, V8\u0027s `SetPrototypeProperties` path updates these existing data properties without invalidating the `PromiseThenLookupChain` protector. `Promise.prototype.finally()` subsequently trusts the stale protector and uses an internal `InvokeThen` fast path that calls the original native `then`, bypassing vm2\u0027s wrapper and its `resetPromiseSpecies(this)` hardening.\n\nThe attacker-controlled species constructor therefore supplies the resolve and reject functions used by a native Promise reaction. A calibrated stack overflow at that native reaction boundary yields a raw host-realm `RangeError` to the attacker-controlled reject function. Its constructor chain reaches the host `Function` constructor and consequently the host `process` object.\n\nThe attached proof is non-destructive: it reads only `process.version`. It does not execute commands, access files, or perform network requests.\n\n## Latest-version status\n\nVerified on 2026-08-14:\n\n- npm `latest`: `vm2@3.11.5`\n- `vm2@3.11.5` publication time: 2026-05-18T15:37:26.138Z\n- npm `gitHead`: `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`\n- npm tarball: `https://registry.npmjs.org/vm2/-/vm2-3.11.5.tgz`\n- npm integrity: `sha512-RSrkBiwrj6FRU+QdqNs6KG0XdlvJCjpQ4GXiqmMbrhmwfu5k/XIMpAer0L8f6iuf0uJ3a4T1xJN126Q8yf0VIA==`\n- GitHub default branch `main` HEAD: the same commit, also tagged `v3.11.5`\n- latest formal Node.js release: `v26.7.0`, V8 `14.6.202.34`\n\nThe npm tarball and current GitHub `main` contain the same relevant `lib/setup-sandbox.js` Git blob. There is no unpublished fix on `main` at the time of this report.\n\nPermanent source reference:\n\n\u003chttps://github.com/patriksimek/vm2/blob/7a1f5100b96f48d34e0fe104ab37c0acc5944f92/lib/setup-sandbox.js#L345-L390\u003e\n\n## Affected configurations\n\n### vm2 versions tested on Node.js 26.7.0\n\n| vm2 version | Result |\n| --- | --- |\n| 3.10.2 through 3.10.5 | host realm reached, 3/3 per release |\n| 3.11.0 | host realm reached, 3/3 |\n| 3.11.1 | host realm reached, 3/3 |\n| 3.11.2 | host realm reached, 5/5 |\n| 3.11.3 | host realm reached, 3/3 |\n| 3.11.4 | host realm reached, 5/5 |\n| 3.11.5 | host realm reached, 5/5 |\n| current `main` (`7a1f5100`) | host realm reached, 5/5 |\n\nThis report therefore confirms **vm2 3.10.2 through 3.11.5** as affected when used with the vulnerable runtime. Earlier vm2 versions are not claimed: they may be independently vulnerable through older published issues, which would not establish this root cause.\n\n### Node.js versions tested with stock vm2 3.11.5\n\n| Node.js | V8 | Result |\n| --- | --- | --- |\n| 22.23.2 | 12.4.254.21 | safe, 5/5 |\n| 24.19.0 | 13.6.233.17 | safe, 5/5 |\n| 25.9.0 | 14.1.146.11 | safe, 5/5 |\n| 26.0.0 | 14.6.202.33 | host realm reached, 5/5 |\n| every formal release from 26.1.0 through 26.7.0 | 14.6.202.34 | host realm reached, 5/5 per release |\n| v27.0.0-nightly202608131b2de5e052 | 14.6.202.34 | host realm reached |\n| v27.0.0-v8-canary20260812f3fe529a1e | 15.3.55 | safe |\n\nThe vulnerable behavior was reproduced on Linux/musl, Linux/glibc, and Windows x64. It is not Alpine-specific.\n\n## Configuration requirements\n\nThe default configuration is affected:\n\n```js\nconst vm = new VM();\n```\n\nDefault `new VM()` was verified 3/3 on Node.js 26.7.0 and vm2 3.11.5 with the operating system\u0027s default Node stack size.\n\nThe escape also remains reproducible with stronger settings:\n\n```js\nconst vm = new VM({\n allowAsync: true,\n eval: false,\n wasm: false,\n timeout: 5000\n});\n```\n\nTherefore the exploit does **not** require:\n\n- WebAssembly or JSPI;\n- dynamic evaluation being enabled;\n- Buffer;\n- an exposed host object;\n- a custom Promise supplied by the embedder;\n- a specific operating system; or\n- any challenge-specific code.\n\nThe demonstrated producer uses an async function, so async support must be available. This is vm2\u0027s default.\n\nThe V8 `PromiseThenLookupChain` protector must still be intact when vm2 installs its wrappers. A fresh/default Node.js process satisfies this condition. An unrelated earlier mutation that correctly invalidates the protector can make this exact path safe, but that is not a documented vm2 mitigation and is not present in the default setup.\n\n## Reproduction\n\nThe attachment `poc.js` uses only the published npm package and prints a benign host-version marker.\n\n```sh\nmkdir vm2-node26-repro\ncd vm2-node26-repro\nnpm init -y\nnpm install --ignore-scripts --no-audit --no-fund vm2@3.11.5\ncp /path/to/poc.js .\nnode poc.js\n```\n\nAlternatively, with the official Node.js 26.7.0 container:\n\n```sh\ndocker run --rm -v \"$PWD:/poc:ro\" -w /tmp node:26.7.0-bookworm-slim sh -lc \u0027\n npm init -y \u003e/dev/null 2\u003e\u00261 \u0026\u0026\n npm install --ignore-scripts --no-audit --no-fund vm2@3.11.5 \u003e/dev/null 2\u003e\u00261 \u0026\u0026\n cp /poc/poc.js . \u0026\u0026\n node poc.js\n\u0027\n```\n\nRepresentative output:\n\n```json\n{\n \"node\": \"v26.7.0\",\n \"v8\": \"14.6.202.34-node.28\",\n \"vm2\": \"3.11.5\",\n \"config\": \"default\",\n \"result\": \"HOST\",\n \"hostVersion\": \"v26.7.0\",\n \"speciesCalls\": 1,\n \"localError\": false,\n \"localRangeError\": false\n}\n```\n\nThe calibrated depth varies with the platform and process layout; this is expected. The PoC searches the boundary instead of relying on a fixed depth.\n\nTo verify that disabling eval and WebAssembly is not sufficient:\n\n```sh\nSTRICT=1 node poc.js\n```\n\n## Technical root cause\n\n1. vm2 replaces the intrinsic `Promise.prototype.then` and `catch` methods with wrappers that sanitize callbacks and execute `resetPromiseSpecies(this)`.\n2. These two prototype writes are consecutive direct assignments in `lib/setup-sandbox.js`.\n3. V8 14.6 enables the `proto_assign_seq_opt` optimization, combining this assignment sequence into `SetPrototypeProperties`.\n4. In the Node.js 26 implementation, the existing-data-property branch calls `Object::SetDataProperty(\u0026it, value)` without first calling `it.UpdateProtector()`.\n5. The JavaScript property now contains vm2\u0027s wrapper, but the V8 `PromiseThenLookupChain` protector incorrectly remains valid.\n6. `Promise.prototype.finally()` performs an internal `InvokeThen`. Because the protector appears valid, V8 directly selects the native Promise `then` instead of performing the observable property lookup that would reach vm2\u0027s wrapper.\n7. The wrapper never executes, so the attacker\u0027s own `constructor[Symbol.species]` is not reset before the native `then` creates its result capability.\n8. A native Promise reaction calls the attacker-provided capability resolve function. At a calibrated stack boundary, V8 creates a host-realm `RangeError` and passes it to the attacker-provided capability reject function without vm2 conversion.\n9. `error.constructor.constructor` is consequently the host `Function`, even when the VM was configured with `eval:false`.\n\nThe root-cause control is strong:\n\n```sh\nnode --no-proto-assign-seq-opt poc.js\n```\n\nOn Node.js 26.7.0 this changes the result from `HOST` to `SAFE` (3/3). A separate semantic probe also changes from `wrapperCalls=0` to `wrapperCalls=1`.\n\n## Relationship to previous advisories\n\nThis report intentionally discloses the overlap with prior work:\n\n### CVE-2026-22709 / GHSA-99p7-6v5w-7xg8\n\nThat issue concerned bypassing callback sanitization on intrinsic Promises returned by async functions. vm2\u0027s fix added/strengthened the `globalPromise.prototype.then` and `catch` wrappers. The current issue is different: on V8 14.6, `finally()` trusts a stale protector and bypasses those installed wrappers at the engine fast path.\n\n### CVE-2026-47208 / GHSA-76w7-j9cq-rx2j\n\nThat issue used a missing `resetPromiseSpecies` call in `localPromise`\u0027s rejection-swallowing tail. It is marked fixed in 3.11.4. The current entry point is the intrinsic async Promise plus `finally()`/`InvokeThen`; the PoC succeeds against 3.11.4 and 3.11.5.\n\n### CVE-2026-47210 / GHSA-6j2x-vhqr-qr7q\n\nThat issue required a JSPI-backed Promise and WebAssembly APIs. Its 3.11.4 fix removes the relevant JSPI surface. The current PoC uses an ordinary fulfilled async-function Promise, works with `wasm:false`, and succeeds against 3.11.5.\n\n### Public V8 fix\n\nThe underlying V8 protector bookkeeping bug is already public and fixed upstream:\n\n- data-property branch: \u003chttps://github.com/v8/v8/commit/7b26e81087ec88c287d9a4812f969d412f32774e\u003e\n- follow-up lazy-accessor branch: \u003chttps://github.com/v8/v8/commit/4635ddd85839461c8ad791990023a477efefe7bd\u003e\n\nThis report does not claim discovery of a new V8 bug. It reports a previously undocumented, still-unpatched vm2 sandbox escape created by the interaction between that V8 bug and vm2\u0027s Promise hardening. The escape affects vm2\u0027s latest release and current main branch.\n\n## Impact\n\nAn attacker who can execute untrusted JavaScript inside a vm2 `VM` can cross the sandbox boundary and obtain the host `Function` constructor and `process` object. This permits arbitrary code execution with the privileges of the host Node.js process, including access to its filesystem, credentials, environment, network, and child-process facilities.\n\nThis is the exact security boundary vm2 is intended to enforce; no additional application mistake is required beyond executing attacker-controlled code in the sandbox.\n\n## Suggested remediation\n\n1. Install the intrinsic `then` and `catch` wrappers through an operation that reliably invalidates V8\u0027s Promise lookup-chain protector, such as an appropriate `Reflect.defineProperty`/`Object.defineProperty` path, instead of the optimizable consecutive direct-assignment sequence.\n2. Wrap the intrinsic `Promise.prototype.finally` entry point and execute `resetPromiseSpecies(this)` before delegating to the cached native `finally` implementation.\n3. Add a build/runtime regression test using an intrinsic Promise from `(async () =\u003e 1)()`: an attacker-controlled own species must not be constructed by `p.finally()`.\n4. Until a vm2 release is available, document Node.js 26 as affected or fail closed on the vulnerable runtime range.\n5. Coordinate with Node.js to backport the existing V8 protector fixes to the Node.js 26 release line.\n\nVerified controls show that wrapping `finally` before calling the cached native implementation blocks the tested direct variants, while the upstream V8 fix also restores correct wrapper invocation.\n\nCredit is requested as: `YMsora`. `https://github.com/YMs0ra`\n\n## Attachments\n[vm2-node26-finally-private-report.zip](https://github.com/user-attachments/files/31059187/vm2-node26-finally-private-report.zip)",
"id": "GHSA-27g9-p43v-cw3v",
"modified": "2026-10-01T15:28:08Z",
"published": "2026-10-01T15:28:07Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-27g9-p43v-cw3v"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92944"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/commit/c7df2e21d2c74038a1f1750f40f9fe603ec69c6a"
},
{
"type": "PACKAGE",
"url": "https://github.com/patriksimek/vm2"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/vm2-3.10.2-through-3.11.6-sandbox-escape-via-promise-protector"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector"
}
GHSA-27RF-8MJP-R363
Vulnerability from github – Published: 2022-10-19 19:00 – Updated: 2022-12-16 16:31Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.
Multiple sandbox bypass vulnerabilities exist in Script Security Plugin and Pipeline: Groovy Plugin:
- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier and in Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier, various casts performed implicitly by the Groovy language runtime were not intercepted by the sandbox. This includes casts performed when returning values from methods, when assigning local variables, fields, properties, and when defining default arguments for closure, constructor, and method parameters (CVE-2022-43401 in Script Security Plugin and CVE-2022-43402 in Pipeline: Groovy Plugin).
- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier, when casting an array-like value to an array type, per-element casts to the component type of the array are not intercepted by the sandbox (CVE-2022-43403).
- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier, crafted constructor bodies and calls to sandbox-generated synthetic constructors can be used to construct any subclassable type (due to an incomplete fix for SECURITY-1754 in the 2020-03-09 security advisory) (CVE-2022-43404).
These vulnerabilities allow attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
These vulnerabilities have been fixed:
- Script Security Plugin 1184.v85d16b_d851b_3 and Pipeline: Groovy Plugin 2803.v1a_f77ffcc773 intercept Groovy casts performed implicitly by the Groovy language runtime (CVE-2022-43401 in Script Security Plugin and CVE-2022-43402 in Pipeline: Groovy Plugin).
- Script Security Plugin 1184.v85d16b_d851b_3 intercepts per-element casts when casting array-like values to array types (CVE-2022-43403).
- Script Security Plugin 1184.v85d16b_d851b_3 rejects improper calls to sandbox-generated synthetic constructors (CVE-2022-43404).
Both plugins, Script Security Plugin and Pipeline: Groovy Plugin must be updated simultaneously. While Script Security Plugin could be updated independently, doing so would cause errors in Pipeline: Groovy Plugin due to an incompatible API change.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c 1184.v85d16b"
},
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:script-security"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1184.v85d16b_d851b_3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 2802.v5ea"
},
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins.workflow:workflow-cps"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2803.v1a_f77ffcc773"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-43404"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": true,
"github_reviewed_at": "2022-10-19T22:04:13Z",
"nvd_published_at": "2022-10-19T16:15:00Z",
"severity": "HIGH"
},
"details": "Script Security Plugin provides a sandbox feature that allows low privileged users to define scripts, including Pipelines, that are generally safe to execute. Calls to code defined inside a sandboxed script are intercepted, and various allowlists are checked to determine whether the call is to be allowed.\n\nMultiple sandbox bypass vulnerabilities exist in Script Security Plugin and Pipeline: Groovy Plugin:\n\n- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier and in Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier, various casts performed implicitly by the Groovy language runtime were not intercepted by the sandbox. This includes casts performed when returning values from methods, when assigning local variables, fields, properties, and when defining default arguments for closure, constructor, and method parameters (CVE-2022-43401 in Script Security Plugin and CVE-2022-43402 in Pipeline: Groovy Plugin).\n- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier, when casting an array-like value to an array type, per-element casts to the component type of the array are not intercepted by the sandbox (CVE-2022-43403).\n- In Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier, crafted constructor bodies and calls to sandbox-generated synthetic constructors can be used to construct any subclassable type (due to an incomplete fix for SECURITY-1754 in the [2020-03-09 security advisory](https://www.jenkins.io/security/advisory/2020-03-09/#SECURITY-1754)) (CVE-2022-43404).\n\nThese vulnerabilities allow attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.\n\nThese vulnerabilities have been fixed:\n\n- Script Security Plugin 1184.v85d16b_d851b_3 and Pipeline: Groovy Plugin 2803.v1a_f77ffcc773 intercept Groovy casts performed implicitly by the Groovy language runtime (CVE-2022-43401 in Script Security Plugin and CVE-2022-43402 in Pipeline: Groovy Plugin).\n- Script Security Plugin 1184.v85d16b_d851b_3 intercepts per-element casts when casting array-like values to array types (CVE-2022-43403).\n- Script Security Plugin 1184.v85d16b_d851b_3 rejects improper calls to sandbox-generated synthetic constructors (CVE-2022-43404).\n\nBoth plugins, Script Security Plugin and Pipeline: Groovy Plugin must be updated simultaneously. While Script Security Plugin could be updated independently, doing so would cause errors in Pipeline: Groovy Plugin due to an incompatible API change.",
"id": "GHSA-27rf-8mjp-r363",
"modified": "2022-12-16T16:31:10Z",
"published": "2022-10-19T19:00:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43404"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2824%20(1)"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2022/10/19/3"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin"
}
GHSA-27RR-R4MX-XR9R
Vulnerability from github – Published: 2022-05-17 00:19 – Updated: 2022-05-17 00:19In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.
{
"affected": [],
"aliases": [
"CVE-2017-3893"
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-693"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-11-14T21:29:00Z",
"severity": "HIGH"
},
"details": "In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.",
"id": "GHSA-27rr-r4mx-xr9r",
"modified": "2022-05-17T00:19:41Z",
"published": "2022-05-17T00:19:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-3893"
},
{
"type": "WEB",
"url": "http://support.blackberry.com/kb/articleDetail?articleNumber=000046674"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-27X6-H354-CFV6
Vulnerability from github – Published: 2026-09-08 21:34 – Updated: 2026-09-10 15:33In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"affected": [],
"aliases": [
"CVE-2026-28658"
],
"database_specific": {
"cwe_ids": [
"CWE-693"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-08T19:17:56Z",
"severity": "HIGH"
},
"details": "In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"id": "GHSA-27x6-h354-cfv6",
"modified": "2026-09-10T15:33:00Z",
"published": "2026-09-08T21:34:15Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28658"
},
{
"type": "WEB",
"url": "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
No mitigation information available for this CWE.
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. An attacker with the ability to access functionality not properly constrained by ACLs can obtain sensitive information and possibly compromise the entire application. Such an attacker can access resources that must be available only to users at a higher privilege level, can access management sections of the application, or can run queries for data that they otherwise not supposed to.
CAPEC-107: Cross Site Tracing
Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server.
CAPEC-127: Directory Indexing
An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. An adversary can use this to explore the directory tree on a target as well as learn the names of files. This can often end up revealing test files, backup files, temporary files, hidden files, configuration files, user accounts, script contents, as well as naming conventions, all of which can be used by an attacker to mount additional attacks.
CAPEC-17: Using Malicious Files
An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example through shell access; or in a possible worst case allows an adversary to upload a file and then execute it. Web servers, ftp servers, and message oriented middleware systems which have many integration points are particularly vulnerable, because both the programmers and the administrators must be in synch regarding the interfaces and the correct privileges for each interface.
CAPEC-20: Encryption Brute Forcing
An attacker, armed with the cipher text and the encryption algorithm used, performs an exhaustive (brute force) search on the key space to determine the key that decrypts the cipher text to obtain the plaintext.
CAPEC-22: Exploiting Trust in Client
An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.
CAPEC-237: Escaping a Sandbox by Calling Code in Another Language
The attacker may submit malicious code of another language to obtain access to privileges that were not intentionally exposed by the sandbox, thus escaping the sandbox. For instance, Java code cannot perform unsafe operations, such as modifying arbitrary memory locations, due to restrictions placed on it by the Byte code Verifier and the JVM. If allowed, Java code can call directly into native C code, which may perform unsafe operations, such as call system calls and modify arbitrary memory locations on their behalf. To provide isolation, Java does not grant untrusted code with unmediated access to native C code. Instead, the sandboxed code is typically allowed to call some subset of the pre-existing native code that is part of standard libraries.
CAPEC-36: Using Unpublished Interfaces or Functionality
An adversary searches for and invokes interfaces or functionality that the target system designers did not intend to be publicly available. If interfaces fail to authenticate requests, the attacker may be able to invoke functionality they are not authorized for.
CAPEC-477: Signature Spoofing by Mixing Signed and Unsigned Content
An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data.
CAPEC-480: Escaping Virtualization
An adversary gains access to an application, service, or device with the privileges of an authorized or privileged user by escaping the confines of a virtualized environment. The adversary is then able to access resources or execute unauthorized code within the host environment, generally with the privileges of the user running the virtualized process. Successfully executing an attack of this type is often the first step in executing more complex attacks.
CAPEC-51: Poison Web Service Registry
SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registry can redirect (think phishing for servers) the service requester to a malicious service provider, provide incorrect information in schema or metadata, and delete information about service provider interfaces.
CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
CAPEC-59: Session Credential Falsification through Prediction
This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.
CAPEC-65: Sniff Application Code
An adversary passively sniffs network communications and captures application code bound for an authorized client. Once obtained, they can use it as-is, or through reverse-engineering glean sensitive information or exploit the trust relationship between the client and server. Such code may belong to a dynamic update to the client, a patch being applied to a client component or any such interaction where the client is authorized to communicate with the server.
CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB)
An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two devices communicating via Bluetooth. The adversary uses an Adversary in the Middle setup to modify packets sent between the two devices during the authentication process, specifically the entropy bits. Knowledge of the number of entropy bits will allow the attacker to easily decrypt information passing over the line of communication.
CAPEC-74: Manipulating State
The adversary modifies state information maintained by the target software or causes a state transition in hardware. If successful, the target will use this tainted state and execute in an unintended manner.
State management is an important function within a software application. User state maintained by the application can include usernames, payment information, browsing history as well as application-specific contents such as items in a shopping cart. Manipulating user state can be employed by an adversary to elevate privilege, conduct fraudulent transactions or otherwise modify the flow of the application to derive certain benefits.
If there is a hardware logic error in a finite state machine, the adversary can use this to put the system in an undefined state which could cause a denial of service or exposure of secure data.
CAPEC-87: Forceful Browsing
An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected.