Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-92938: vm2 lets sandboxed code run native code via sqlite

CVE-2026-92938 · published 23 days ago
Summary

Versions of the vm2 library (3.11.3‑3.11.6) allow code that should be isolated to load a native SQLite library and execute it inside the main Node.js process. This breaks the sandbox and could let an attacker run any code with the same rights as the host application. Upgrade vm2 to version 3.11.7 or later to close the gap.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 >= 3.11.3, <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and the runtime strips only one 'node:' prefix, so a sandbox request for 'node:node:sqlite' resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process's privileges. The issue is fixed in vm2 3.11.7.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92938 · MITRE
Track software like this
Free during beta