Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-92946: vm2 can let sandboxed code run any host command

CVE-2026-92946 · published 23 days ago
Summary

The vm2 library for Node.js lets code run in a sandbox, but if the setting to allow external modules is used without locking down the root folder, the sandbox can break out and execute any command on the server. This could let an attacker take control of the system. Update vm2 to the latest version or disable the unsafe external module option and set a proper root folder to stop the problem.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92946 · MITRE
Track software like this
Free during beta