DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92952: CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak

CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak

Vulnerability ID: CVE-2026-92952
CVSS Score: 8.9
Published: 2026-10-01

A high-severity sandbox escape and state corruption vulnerability exists in the vm2 library (versions 3.11.4 through 3.11.6). The vulnerability is caused by an incomplete blocklist of Node.js-internal registered symbols crossing the sandbox-host bridge boundary. Specifically, the filters in lib/setup-sandbox.js and write traps in lib/bridge.js omitted the symbols nodejs.stream.disturbed and nodejs.stream.errored, allowing untrusted code within the sandbox to corrupt host-realm stream state checks.

TL;DR

An incomplete blocklist of Node.js-internal symbols in vm2 (3.11.4-3.11.6) allows sandboxed code to access host-realm stream symbols, corrupt stream state accessors on the host, and bypass security gates.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-669
  • Attack Vector: Adjacent/Remote dependent on application exposure
  • CVSS v4.0 Score: 8.9
  • EPSS Score: 0.00461 (Percentile: 37.62%)
  • Impact: High Integrity Impact / Sandbox Escape
  • Exploit Status: PoC / Non-weaponized
  • KEV Status: Not Listed

Affected Systems

  • vm2 library (versions 3.11.4 through 3.11.6) running on Node.js runtimes containing web streams
  • vm2: >= 3.11.4, <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: a45444d

Fix dangerous-symbol filtering bypass (GHSA-jf8q-945g-9q4c) by utilizing a namespace-based catch-all check.

Exploit Details

  • GitHub: The advisory contains structural details and unit test definitions showing how the bypass behaves on modern Node.js versions.

Mitigation Strategies

  • Upgrade vm2 dependency to version 3.11.7 immediately to apply namespace symbol filtering.
  • Migrate to process-isolated script execution architectures such as isolated-vm or isolated container sandboxes.
  • Implement strong input validation to prevent user-supplied script execution within single-isolate virtual machines.

Remediation Steps:

  1. Identify all direct and transitive dependencies on vm2 in package.json files.
  2. Update the vm2 dependency to version 3.11.7 using npm install vm2@3.11.7 or yarn upgrade vm2@3.11.7.
  3. Validate host application behaviors by executing unit tests on stream handling mechanisms.
  4. Plan and execute an architecture migration to replace deprecated vm2 isolates with subprocess boundaries.

References


Read the full report for CVE-2026-92952 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)