<Vulnerability name="CVE-2026-92963">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-17T13:46:18</PublicDate>
    <Bugzilla id="2536030" url="https://bugzilla.redhat.com/show_bug.cgi?id=2536030" xml:lang="en:us">
vm2: vm2: Sensitive information disclosure due to internal state access
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-767</CWE>
    <Details xml:lang="en:us" source="Mitre">
vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in vm2. An attacker can exploit this vulnerability by improperly accessing the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable through globalThis. This allows the attacker to retrieve sensitive internal information from the sandbox environment, leading to information disclosure.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact information disclosure vulnerability in vm2 allows attackers to access sensitive sandbox internals. However, Red Hat products are not affected by this flaw as the vulnerable code is not present in Red Hat's supported offerings.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhdh/rhdh-hub-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>ansible-automation-platform/automation-portal</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>ansible-automation-platform/bootc-automation-portal-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-92963
https://nvd.nist.gov/vuln/detail/CVE-2026-92963
https://github.com/patriksimek/vm2/security/advisories/GHSA-2cm2-m3w5-gp2f
https://www.vulncheck.com/advisories/vm2-before-3.11.2-information-disclosure-via-internal-state
    </References>
</Vulnerability>