← العودة للجدول
CVE-2026-47140
CVE-2026-47140 — GHSA: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
📅 2026-05-29
🔴 Critical 🔥 No GHSA PoC Research Exploit CVSS 10

📋 الوصف الكامل

## Summary `NodeVM` blocks several dangerous Node.js builtins such as `module`, `worker_threads`, `cluster`, `vm`, `repl`, and `inspector`. However, the denylist misses `process` and `inspector/promises`. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. ## D

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-47140

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←