DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92948: CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

Vulnerability ID: CVE-2026-92948
CVSS Score: 9.9
Published: 2026-10-01

CVE-2026-92948 is a critical sandbox escape vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6 when executed on Node.js 24 and newer. The vulnerability allows an attacker to bypass built-in module blocking defenses by double-prefixing a restricted module name (such as node:node:test). This permits the loading of the node:test module, whose test runner execution can be leveraged to execute arbitrary shell commands outside the VM sandbox.

TL;DR

A critical sandbox escape in vm2 (versions >=3.9.6 to <=3.11.6) allows attackers to execute arbitrary system commands on the host by leveraging a prefix-stripping flaw to import the 'node:test' core module on Node.js 24+.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-693
  • Attack Vector: Network
  • CVSS Score: 9.9 (Critical)
  • EPSS Score: 0.00654
  • Impact: Complete Sandbox Escape & Host Remote Code Execution
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed

Affected Systems

  • vm2 (npm package) running on Node.js 24+
  • vm2: >= 3.9.6, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: 415339f

Fix GHSA-qhwx-74w5-xhxq: sanitize input and block dangerous builtins recursively

Exploit Details

Mitigation Strategies

  • Upgrade vm2 to version 3.11.7 or later to apply recursive prefix validation.
  • Explicitly remove wildcard ('*') and 'node:test' from the VM's builtin allowlist.
  • Migrate to isolated-vm to use secure V8 isolate-based boundaries instead of vm2.
  • Execute untrusted code within secure container environments (e.g., Docker, gVisor) to limit host system exposure.

Remediation Steps:

  1. Identify all microservices and dependencies utilizing the vm2 npm package.
  2. Update package.json to specify vm2 version 3.11.7 or newer, then execute 'npm install'.
  3. Inspect NodeVM configurations to ensure the 'builtin' array does not contain '*' or 'node:test'.
  4. Plan the deprecation of vm2 in favor of a containerized execution model or isolated-vm.

References


Read the full report for CVE-2026-92948 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)