CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak
Vulnerability ID: CVE-2026-92952
CVSS Score: 8.9
Published: 2026-10-01
A high-severity sandbox escape and state corruption vulnerability exists in the vm2 library (versions 3.11.4 through 3.11.6). The vulnerability is caused by an incomplete blocklist of Node.js-internal registered symbols crossing the sandbox-host bridge boundary. Specifically, the filters in lib/setup-sandbox.js and write traps in lib/bridge.js omitted the symbols nodejs.stream.disturbed and nodejs.stream.errored, allowing untrusted code within the sandbox to corrupt host-realm stream state checks.
TL;DR
An incomplete blocklist of Node.js-internal symbols in vm2 (3.11.4-3.11.6) allows sandboxed code to access host-realm stream symbols, corrupt stream state accessors on the host, and bypass security gates.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-669
- Attack Vector: Adjacent/Remote dependent on application exposure
- CVSS v4.0 Score: 8.9
- EPSS Score: 0.00461 (Percentile: 37.62%)
- Impact: High Integrity Impact / Sandbox Escape
- Exploit Status: PoC / Non-weaponized
- KEV Status: Not Listed
Affected Systems
- vm2 library (versions 3.11.4 through 3.11.6) running on Node.js runtimes containing web streams
-
vm2: >= 3.11.4, <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: a45444d
Fix dangerous-symbol filtering bypass (GHSA-jf8q-945g-9q4c) by utilizing a namespace-based catch-all check.
Exploit Details
- GitHub: The advisory contains structural details and unit test definitions showing how the bypass behaves on modern Node.js versions.
Mitigation Strategies
- Upgrade vm2 dependency to version 3.11.7 immediately to apply namespace symbol filtering.
- Migrate to process-isolated script execution architectures such as isolated-vm or isolated container sandboxes.
- Implement strong input validation to prevent user-supplied script execution within single-isolate virtual machines.
Remediation Steps:
- Identify all direct and transitive dependencies on vm2 in package.json files.
- Update the vm2 dependency to version 3.11.7 using npm install vm2@3.11.7 or yarn upgrade vm2@3.11.7.
- Validate host application behaviors by executing unit tests on stream handling mechanisms.
- Plan and execute an architecture migration to replace deprecated vm2 isolates with subprocess boundaries.
References
- NVD Record for CVE-2026-92952
- GitHub Security Advisory GHSA-jf8q-945g-9q4c
- vm2 v3.11.7 Release Notes
- VulnCheck Advisory Portal
Read the full report for CVE-2026-92952 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)