Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-92948: vm2 lets code escape sandbox on Node 24
CVE-2026-92948 · published 23 days ago
Summary
Versions of vm2 from 3.9.6 through 3.11.6 can be tricked into running code outside its safe environment when used with Node.js version 24 or newer. An attacker could cause the host system to execute arbitrary JavaScript, potentially leading to unauthorized actions. Upgrade vm2 to version 3.11.7 or later to close the gap.
What to do
- Update vm2 to version 3.11.7.
- Update vm2 to version 3.10.5-aikido.8.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.8.
- Update patriksimek vm2 to version 3.11.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.7 |
| npm | – | vm2 |
>= 3.9.6, <= 3.11.6 Fix: upgrade to 3.11.7
|
| Root:npm | – | vm2 |
< 3.10.5-aikido.8 Fix: upgrade to 3.10.5-aikido.8
|
| Root:npm | rootio | @rootio/vm2 |
< 3.10.5-root.io.8 Fix: upgrade to 3.10.5-root.io.8
|
Original advisory text
CVE-2026-92948 in vm2 - Patched by Root
vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq
- https://www.vulncheck.com/advisories/vm2-3.9.6-through-3.11.5-sandbox-escape-via...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92948... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92948
- https://github.com/advisories/GHSA-qhwx-74w5-xhxq
- https://github.com/patriksimek/vm2/commit/415339f698f0d52d3c5ad358b12b79c8072d5b...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta