DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92945: CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

Vulnerability ID: CVE-2026-92945
CVSS Score: 4.2
Published: 2026-10-01

A module allowlist bypass vulnerability (CVE-2026-92945 / GHSA-7q3f-wx44-378m) was identified in the vm2 sandboxing library prior to version 3.11.7. This flaw permits unauthenticated or untrusted code running within the sandbox environment to bypass explicit module restrictions. When the transitive resolution option is disabled, the system fails to validate file system path boundaries, allowing prefix-sharing sibling directories to be resolved and loaded, thereby escaping intended sandbox restrictions.

TL;DR

A path traversal and module allowlist bypass flaw in vm2's legacy resolver allows sandboxed code to load un-allowlisted sibling packages that share a lexical prefix with allowlisted modules.


⚠️ Exploit Status: POC

Technical Details

  • Vulnerability ID: CVE-2026-92945 / GHSA-7q3f-wx44-378m
  • CWE ID: CWE-22 (Path Traversal), CWE-863 (Incorrect Authorization)
  • Attack Vector: Network (AV:N)
  • Attack Complexity: High (AC:H)
  • CVSS v3.1 Score: 4.2 (Medium)
  • EPSS Score: 0.00277 (18.25th percentile)
  • Exploit Status: Proof of Concept available
  • CISA KEV Status: Not listed

Affected Systems

  • vm2 Node.js sandboxing library
  • vm2: >= 0, < 3.11.7 (Fixed in: 3.11.7)

Exploit Details

Mitigation Strategies

  • Upgrade vm2 to 3.11.7 or later.
  • Avoid using 'transitive: false' options with shared sibling directories.
  • Employ strict path normalization and canonicalization before verification checks.

Remediation Steps:

  1. Identify vulnerable vm2 dependencies using 'npm audit' or 'yarn audit'.
  2. Update the dependency declaration of vm2 in package.json to '^3.11.7'.
  3. Verify that no prefix-sharing modules exist alongside sandboxed dependencies in the deployment environment.

References


Read the full report for CVE-2026-92945 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)