DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92938: CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

Vulnerability ID: CVE-2026-92938
CVSS Score: 9.9
Published: 2026-10-01

CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.

TL;DR

A critical sandbox escape in vm2 allowed attackers to execute native shellcode outside the sandbox by loading raw, unsanitized versions of the Node.js built-in node:sqlite module via nested protocol prefixes and function-based properties options bypasses.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-693
  • Attack Vector: Network / Input-driven
  • CVSS v3.1 Score: 9.9 (Critical)
  • CVSS v4.0 Score: 9.4 (Critical)
  • EPSS Score: 0.00616 (Percentile: 47.61%)
  • Exploit Status: Proof-of-Concept fully verified
  • CISA KEV Status: Not Listed

Affected Systems

  • vm2 (npm package)
  • vm2: >= 3.11.3, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: aa146a7

Wrap and sanitize DatabaseSync option parameters in vm2 to enforce disable load extension. Also prevent double-prefix node: imports

Exploit Details

  • GitHub Security Advisory: Full vulnerability details and official regression test cases showing sandbox escape vectors via node:sqlite.

Mitigation Strategies

  • Upgrade vm2 to version 3.11.7 or later immediately.
  • Modify NodeVM configurations to restrict built-in module imports to a strict allowlist that excludes node:sqlite.
  • Migrate applications from the deprecated vm2 library to isolated sandbox technologies such as isolated-vm or process-level microVMs.

Remediation Steps:

  1. Identify all projects containing vm2 as a direct or nested dependency.
  2. Update package.json dependencies to target version 3.11.7 or higher.
  3. Rebuild dependency trees using npm install or yarn install to clear cached vulnerable packages.
  4. Review the NodeVM configuration settings to ensure no wildcard built-in definitions are active.

References


Read the full report for CVE-2026-92938 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)