Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-92951: vm2 can load unauthorized host packages
CVE-2026-92951 · published 23 days ago
Summary
The vm2 sandbox library (versions before 3.11.7) does not correctly verify the exact names of allowed external packages. An attacker could trick it by using a package whose name contains an allowed name as a substring, causing vm2 to load and run code it should block. Update vm2 to version 3.11.7 or later to fix the check.
What to do
- Update vm2 to version 3.11.7.
- Update vm2 to version 3.10.5-aikido.8.
- Update rootio @rootio/vm2 to version 3.10.5-root.io.8.
- Update patriksimek vm2 to version 3.11.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.7 |
| npm | – | vm2 |
<= 3.11.6 Fix: upgrade to 3.11.7
|
| Root:npm | – | vm2 |
< 3.10.5-aikido.8 Fix: upgrade to 3.10.5-aikido.8
|
| Root:npm | rootio | @rootio/vm2 |
< 3.10.5-root.io.8 Fix: upgrade to 3.10.5-root.io.8
|
Original advisory text
CVE-2026-92951 in vm2 - Patched by Root
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.
References
- https://github.com/advisories/GHSA-c48m-32m9-vx93
- https://github.com/patriksimek/vm2/security/advisories/GHSA-c48m-32m9-vx93
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-module-allowlist-bypass-v...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92951... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92951
- https://github.com/patriksimek/vm2/commit/ab4ee7d803e8c80155e9eb3672226bddbca4aa...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-706Use of Incorrectly-Resolved Name or Reference
CWE-829Inclusion of Functionality from Untrusted Control Sphere
CWE-863Incorrect Authorization
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta