Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-92956: vm2 sandbox can break out and access host files
CVE-2026-92956 · published 23 days ago
Summary
Versions of vm2 from 3.10.1 to 3.11.6 let code run inside the default sandbox escape to the real Node.js environment. An attacker could then read or modify files on the server. Upgrade vm2 to version 3.11.7 or later to close the escape.
What to do
- Update vm2 to version 3.11.7.
- Update patriksimek vm2 to version 3.11.7 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.11.7 |
| npm | – | vm2 |
>= 3.10.1, <= 3.11.6 Fix: upgrade to 3.11.7
|
Original advisory text
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-wjwh-qqvp-g4p4
- https://www.vulncheck.com/advisories/vm2-3.10.1-through-3.11.6-sandbox-escape-vi...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92956... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92956
- https://github.com/patriksimek/vm2/commit/cb85599e4470afa308e7c807b5c6b3ec9bf58b...
- https://github.com/patriksimek/vm2/blob/415339f698f0d52d3c5ad358b12b79c8072d5b4b...
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://github.com/advisories/GHSA-wjwh-qqvp-g4p4
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-693Protection Mechanism Failure
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta