Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-92948: vm2 lets code escape sandbox on Node 24

CVE-2026-92948 · published 23 days ago
Summary

Versions of vm2 from 3.9.6 through 3.11.6 can be tricked into running code outside its safe environment when used with Node.js version 24 or newer. An attacker could cause the host system to execute arbitrary JavaScript, potentially leading to unauthorized actions. Upgrade vm2 to version 3.11.7 or later to close the gap.

What to do
  • Update vm2 to version 3.11.7.
  • Update vm2 to version 3.10.5-aikido.8.
  • Update rootio @rootio/vm2 to version 3.10.5-root.io.8.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 >= 3.9.6, <= 3.11.6
Fix: upgrade to 3.11.7
Root:npm – vm2 < 3.10.5-aikido.8
Fix: upgrade to 3.10.5-aikido.8
Root:npm rootio @rootio/vm2 < 3.10.5-root.io.8
Fix: upgrade to 3.10.5-root.io.8
Original advisory text
CVE-2026-92948 in vm2 - Patched by Root
vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta