CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test
Vulnerability ID: CVE-2026-92948
CVSS Score: 9.9
Published: 2026-10-01
CVE-2026-92948 is a critical sandbox escape vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6 when executed on Node.js 24 and newer. The vulnerability allows an attacker to bypass built-in module blocking defenses by double-prefixing a restricted module name (such as node:node:test). This permits the loading of the node:test module, whose test runner execution can be leveraged to execute arbitrary shell commands outside the VM sandbox.
TL;DR
A critical sandbox escape in vm2 (versions >=3.9.6 to <=3.11.6) allows attackers to execute arbitrary system commands on the host by leveraging a prefix-stripping flaw to import the 'node:test' core module on Node.js 24+.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-693
- Attack Vector: Network
- CVSS Score: 9.9 (Critical)
- EPSS Score: 0.00654
- Impact: Complete Sandbox Escape & Host Remote Code Execution
- Exploit Status: Proof-of-Concept Available
- KEV Status: Not Listed
Affected Systems
- vm2 (npm package) running on Node.js 24+
-
vm2: >= 3.9.6, <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: 415339f
Fix GHSA-qhwx-74w5-xhxq: sanitize input and block dangerous builtins recursively
Exploit Details
- GitHub Security Advisory: Vulnerability disclosure detailing the node:test sandbox escape exploit vector.
Mitigation Strategies
- Upgrade vm2 to version 3.11.7 or later to apply recursive prefix validation.
- Explicitly remove wildcard ('*') and 'node:test' from the VM's builtin allowlist.
- Migrate to isolated-vm to use secure V8 isolate-based boundaries instead of vm2.
- Execute untrusted code within secure container environments (e.g., Docker, gVisor) to limit host system exposure.
Remediation Steps:
- Identify all microservices and dependencies utilizing the vm2 npm package.
- Update package.json to specify vm2 version 3.11.7 or newer, then execute 'npm install'.
- Inspect NodeVM configurations to ensure the 'builtin' array does not contain '*' or 'node:test'.
- Plan the deprecation of vm2 in favor of a containerized execution model or isolated-vm.
References
Read the full report for CVE-2026-92948 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)