Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-92955: vm2 NodeVM sandbox escape lets attackers run code

CVE-2026-92955 · published 23 days ago
Summary

The vm2 library used to isolate JavaScript code (specifically its NodeVM feature) can be tricked into exposing internal system objects. An attacker could overwrite core functions and make the host program execute arbitrary code, bypassing the intended safety checks. Upgrade vm2 to version 3.11.8 or later to fix the issue.

What to do
  • Update vm2 to version 3.11.8.
  • Update patriksimek vm2 to version 3.11.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.8
npm – vm2 <= 3.11.7
< 3.11.8
Fix: upgrade to 3.11.8
Original advisory text
vm2: Sandbox Escape (NodeVM)
vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta