CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape
Vulnerability ID: CVE-2026-92938
CVSS Score: 9.9
Published: 2026-10-01
CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.
TL;DR
A critical sandbox escape in vm2 allowed attackers to execute native shellcode outside the sandbox by loading raw, unsanitized versions of the Node.js built-in node:sqlite module via nested protocol prefixes and function-based properties options bypasses.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-693
- Attack Vector: Network / Input-driven
- CVSS v3.1 Score: 9.9 (Critical)
- CVSS v4.0 Score: 9.4 (Critical)
- EPSS Score: 0.00616 (Percentile: 47.61%)
- Exploit Status: Proof-of-Concept fully verified
- CISA KEV Status: Not Listed
Affected Systems
- vm2 (npm package)
-
vm2: >= 3.11.3, <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: aa146a7
Wrap and sanitize DatabaseSync option parameters in vm2 to enforce disable load extension. Also prevent double-prefix node: imports
Exploit Details
- GitHub Security Advisory: Full vulnerability details and official regression test cases showing sandbox escape vectors via node:sqlite.
Mitigation Strategies
- Upgrade vm2 to version 3.11.7 or later immediately.
- Modify NodeVM configurations to restrict built-in module imports to a strict allowlist that excludes node:sqlite.
- Migrate applications from the deprecated vm2 library to isolated sandbox technologies such as isolated-vm or process-level microVMs.
Remediation Steps:
- Identify all projects containing vm2 as a direct or nested dependency.
- Update package.json dependencies to target version 3.11.7 or higher.
- Rebuild dependency trees using npm install or yarn install to clear cached vulnerable packages.
- Review the NodeVM configuration settings to ensure no wildcard built-in definitions are active.
References
- GitHub Security Advisory GHSA-6w8r-xxw2-g3hx
- Official Patch Commit
- Official Release v3.11.7
- VulnCheck Advisory
- NVD CVE Record
- CVE.org Authoritative Record
Read the full report for CVE-2026-92938 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)