THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m5w8-4gq2-6f8x (critical) — vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

[GHSA] GHSA-m5w8-4gq2-6f8x (critical) — vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

highgithub_advisoriesPublished 2026-08-17

GHSA-m5w8-4gq2-6f8x Severity: critical CVE: None

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

# NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

**CWE**: CWE-200 (Exposure of Sensi

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m5w8-4gq2-6f8x