DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92935: CVE-2026-92935: Remote Code Execution via Array-Shaped Require Config in vm2 NodeVM Sandbox

CVE-2026-92935: Remote Code Execution via Array-Shaped Require Config in vm2 NodeVM Sandbox

Vulnerability ID: CVE-2026-92935
CVSS Score: 9.5
Published: 2026-10-01

CVE-2026-92935 is a critical sandbox escape and remote code execution vulnerability in the vm2 library. By supplying an array or exotic object to the require property of NodeVM while nesting is enabled, attackers can bypass security checks, load the host vm2 module, and run arbitrary shell commands on the hosting server.

TL;DR

A flaw in type-checking inside vm2 allows attackers to bypass sandbox nesting guards using array-shaped require options, gaining access to host Node.js modules and achieving full remote code execution.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-697 (Incorrect Comparison)
  • Attack Vector: Network
  • CVSS v4.0 Score: 9.5 (Critical)
  • EPSS Score: 0.00673
  • Impact: Sandbox Escape & Remote Code Execution
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications utilizing the vm2 sandbox library
  • vm2: >= 3.11.4, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: 05894ec

Fix NodeVM nesting guard for array-shaped require options

Mitigation Strategies

  • Upgrade vm2 to version 3.11.7 or later to enforce strict prototype validation.
  • Migrate to active sandbox technologies such as isolate-vm or secure containers.
  • Sanitize construction arguments dynamically to reject non-plain configuration objects.

Remediation Steps:

  1. Open the project package.json and update the vm2 version requirement to ^3.11.7.
  2. Run your package manager install command (e.g., npm install or yarn install) to pull the secure package.
  3. Verify the runtime behavior of your application to ensure nested require environments fail shut on array inputs.
  4. Plan long-term deprecation of vm2 dependencies in favor of native OS-level container isolation.

References


Read the full report for CVE-2026-92935 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)