CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2
Vulnerability ID: CVE-2026-92951
CVSS Score: 9.9
Published: 2026-10-01
An incorrect authorization and directory traversal vulnerability in the vm2 library before version 3.11.7 allows remote attackers to bypass the sandbox's external package allowlist. This flaw permits sandboxed code to resolve and execute arbitrary packages available on the host filesystem under host privileges, leading to unauthenticated sandbox escape and host code execution.
TL;DR
A flaw in vm2's bare-specifier matcher allowlist check allows sandbox escape. It uses unanchored substring matching and fails to filter directory traversal sequences, allowing untrusted code to load and execute arbitrary host packages with full authority.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-706, CWE-863, CWE-829
- Attack Vector: Network
- CVSS v3.1 Score: 9.9 (Critical)
- Exploit Status: Proof of Concept (PoC) documented in test suite
- CISA KEV Status: Not Listed
- EPSS Score: 0.00539
- Impact: Complete Sandbox Escape & Host Code Execution
Affected Systems
- Applications executing untrusted code using vm2 NodeVM configurations
- Multi-tenant plugin hosting systems relying on vm2 external module allowlists
- Serverless runtimes and webhooks using deprecated vm2 sandbox instances
-
vm2: < 3.11.7 (Fixed in:
3.11.7)
Code Analysis
Commit: ab4ee7d
Security fix for external-package allowlist bypass in LegacyResolver
@@ -109,7 +109,16 @@\n\t\tthis.externalCache = externals.map(pattern => new RegExp('^(?:' + makeExternalMatcherRegex(pattern) + ')(?:[\\\\/].*)?$'));\n@@ -184,6 +193,18 @@\n\t\t\tif (x.split(/[\\/]/).indexOf('..') !== -1) return undefined;
Exploit Details
- GitHub security advisory test cases: Functional unit tests demonstrating unanchored regex match and path traversal validation bypasses
Mitigation Strategies
- Upgrade vm2 to version 3.11.7 or later where the boundaries of external matchers are strictly anchored and traversal sequences are rejected.
- Migrate to robust isolation mechanisms such as isolates (e.g., isolated-vm), WebAssembly (WASM) runtimes, or containerized execution.
- Implement strong OS-level sandboxing (such as AppArmor, gVisor, or Docker with non-root configurations) to limit the damage of an escape.
Remediation Steps:
- Identify all direct and transitive dependencies on the 'vm2' package in your project's lockfile.
- Update the package.json dependency for 'vm2' to '^3.11.7'.
- Run your package manager's installation command (e.g., 'npm install' or 'yarn install') to apply the patch.
- Verify that the compiled regex mappings inside 'lib/resolver-compat.js' match the anchored patterns.
References
Read the full report for CVE-2026-92951 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)