Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-92955: vm2 NodeVM sandbox escape lets attackers run code
CVE-2026-92955 · published 23 days ago
Summary
The vm2 library used to isolate JavaScript code (specifically its NodeVM feature) can be tricked into exposing internal system objects. An attacker could overwrite core functions and make the host program execute arbitrary code, bypassing the intended safety checks. Upgrade vm2 to version 3.11.8 or later to fix the issue.
What to do
- Update vm2 to version 3.11.8.
- Update patriksimek vm2 to version 3.11.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.8 |
| npm | – | vm2 |
<= 3.11.7 < 3.11.8 Fix: upgrade to 3.11.8
|
Original advisory text
vm2: Sandbox Escape (NodeVM)
vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.
References
- https://github.com/patriksimek/vm2/releases/tag/v3.11.8 URL
- https://github.com/patriksimek/vm2/security/advisories/GHSA-88hf-g992-jg85
- https://www.vulncheck.com/advisories/vm2-before-3.11.8-sandbox-escape-via-nodevm
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92955... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92955 Vendor Advisory
- https://github.com/patriksimek/vm2/commit/22a43704c04b66823b4064b8a16fe1ad54ad02... URL
- https://github.com/patriksimek/vm2/blob/v3.11.7/lib/bridge.js#L1963-L1989 URL
- https://github.com/advisories/GHSA-88hf-g992-jg85
- https://github.com/patriksimek/vm2 Product
- https://github.com/patriksimek/vm2/blob/v3.11.7/lib/setup-node-sandbox.js#L437-L... URL
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92955 · NVD
CVE-2026-92955 · MITRE
CVE-2026-92955 · OSV
GHSA-88hf-g992-jg85 · GHSA
GHSA-88hf-g992-jg85 · OSV
Track software like this
Free during beta