Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-93605: vm2 sandbox lets attackers run host commands
CVE-2026-93605 · published 22 days ago
Summary
Versions of the vm2 library before the latest update let a specially crafted script break out of its safe environment and start programs on the server. This can happen when the library is set to allow all built‑in features or when the child_process feature is explicitly permitted. Update vm2 to the newest version or restrict the built‑in functions to prevent this behavior.
What to do
- Update vm2 to version 3.12.1.
- Update patriksimek vm2 to version 3.12.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | patriksimek | vm2 | < 3.12.1 |
| npm | – | vm2 |
<= 3.12.0 Fix: upgrade to 3.12.1
|
Original advisory text
vm2 contains a sandbox escape vulnerability
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
References
- https://github.com/advisories/GHSA-pq68-rvw4-xp4r
- https://www.vulncheck.com/advisories/vm2-nodevm-before-3.12.1-remote-code-execut...
- https://nvd.nist.gov/vuln/detail/CVE-2026-93605
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93605... Vendor Advisory
- https://github.com/patriksimek/vm2/security/advisories/GHSA-pq68-rvw4-xp4r
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-693Protection Mechanism Failure
CWE-913Improper Control of Dynamically-Managed Code Resources
Timeline
Published18 Sep 2026
Updated9 Oct 2026
First seen18 Sep 2026
Track software like this
Free during beta