CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2
Vulnerability ID: CVE-2026-92945
CVSS Score: 4.2
Published: 2026-10-01
A module allowlist bypass vulnerability (CVE-2026-92945 / GHSA-7q3f-wx44-378m) was identified in the vm2 sandboxing library prior to version 3.11.7. This flaw permits unauthenticated or untrusted code running within the sandbox environment to bypass explicit module restrictions. When the transitive resolution option is disabled, the system fails to validate file system path boundaries, allowing prefix-sharing sibling directories to be resolved and loaded, thereby escaping intended sandbox restrictions.
TL;DR
A path traversal and module allowlist bypass flaw in vm2's legacy resolver allows sandboxed code to load un-allowlisted sibling packages that share a lexical prefix with allowlisted modules.
⚠️ Exploit Status: POC
Technical Details
- Vulnerability ID: CVE-2026-92945 / GHSA-7q3f-wx44-378m
- CWE ID: CWE-22 (Path Traversal), CWE-863 (Incorrect Authorization)
- Attack Vector: Network (AV:N)
- Attack Complexity: High (AC:H)
- CVSS v3.1 Score: 4.2 (Medium)
- EPSS Score: 0.00277 (18.25th percentile)
- Exploit Status: Proof of Concept available
- CISA KEV Status: Not listed
Affected Systems
- vm2 Node.js sandboxing library
-
vm2: >= 0, < 3.11.7 (Fixed in:
3.11.7)
Exploit Details
- GitHub Security Advisory: Details the bypass mechanism with built-in regression tests.
Mitigation Strategies
- Upgrade vm2 to 3.11.7 or later.
- Avoid using 'transitive: false' options with shared sibling directories.
- Employ strict path normalization and canonicalization before verification checks.
Remediation Steps:
- Identify vulnerable vm2 dependencies using 'npm audit' or 'yarn audit'.
- Update the dependency declaration of vm2 in package.json to '^3.11.7'.
- Verify that no prefix-sharing modules exist alongside sandboxed dependencies in the deployment environment.
References
- GitHub Security Advisory GHSA-7q3f-wx44-378m
- Fix Commit 6ac3916da84e060c403e407b6b6318fcc66b0e72
- vm2 Release v3.11.7
- VulnCheck Security Advisory
- NVD - CVE-2026-92945
Read the full report for CVE-2026-92945 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)