Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-92950: vm2 command line tool can run code on host system

CVE-2026-92950 · published 24 days ago
Summary

Versions of vm2 earlier than 3.11.7 let a specially crafted script passed to its command‑line interface break out of the sandbox and run code in the main Node.js process. This could let an attacker access files and run programs on the server. Update vm2 to version 3.11.7 or later to stop the problem.

What to do
  • Update vm2 to version 3.11.7.
  • Update vm2 to version 3.10.5-aikido.8.
  • Update rootio @rootio/vm2 to version 3.10.5-root.io.8.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 <= 3.11.6
Fix: upgrade to 3.11.7
Root:npm – vm2 < 3.10.5-aikido.8
Fix: upgrade to 3.10.5-aikido.8
Root:npm rootio @rootio/vm2 < 3.10.5-root.io.8
Fix: upgrade to 3.10.5-root.io.8
Original advisory text
CVE-2026-92950 in vm2 - Patched by Root
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-453Insecure Default Variable Initialization
CWE-829Inclusion of Functionality from Untrusted Control Sphere
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta