Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-92960: vm2 sandbox can reveal host identity and hijack DNS

CVE-2026-92960 · published 23 days ago
Summary

The vm2 library used in GitHub Actions lets sandboxed code see the host’s operating‑system details and network layout when it’s configured with a permissive setting. An attacker could change the DNS servers for the whole host, causing all future name lookups to go through a malicious resolver. Update vm2 to version 3.11.6 or later to block this behavior.

What to do
  • Update GitHub Actions vm2 to version 3.11.6.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions vm2 <= 3.11.5
Fix: upgrade to 3.11.6
Original advisory text
vm2 before 3.11.6 Process-wide State Exposure via os and dns
vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.4 Critical
Type
CWE-200Information Exposure
CWE-285Improper Authorization
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published17 Sep 2026
Updated19 Sep 2026
First seen17 Aug 2026
Sources
Track software like this
Free during beta