Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-92957: vm2 sandbox can let code run system commands

CVE-2026-92957 · published 23 days ago
Summary

Versions of the vm2 sandbox library up to 3.11.6 do not correctly block the built‑in child_process module, even when the configuration says it should. This lets code running inside the sandbox start programs or execute commands on the host machine. Upgrade vm2 to version 3.11.7 or later, or carefully review and test your sandbox settings to ensure dangerous modules are truly blocked.

What to do
  • Update vm2 to version 3.11.7.
  • Update patriksimek vm2 to version 3.11.7 or later.
Affected software
Ecosystem VendorProductAffected versions
– patriksimek vm2 < 3.11.7
npm – vm2 <= 3.11.6
Fix: upgrade to 3.11.7
Original advisory text
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-269Improper Privilege Management
CWE-284Improper Access Control
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-92957 · MITRE
Track software like this
Free during beta