DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92958: CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem

CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem

Vulnerability ID: CVE-2026-92958
CVSS Score: 8.5
Published: 2026-10-01

CVE-2026-92958 is a high-severity sandbox escape and denylist bypass vulnerability within the NodeVM subsystem of the vm2 sandboxing library. When configuring wildcards with negative deny entries, exact-string matches fail to block subpaths like fs/promises. Sandboxed code can import these subpaths to bypass isolation and execute arbitrary filesystem operations on the host.

TL;DR

A denylist bypass vulnerability in vm2 <= 3.11.6 allows sandboxed code to bypass security rules by importing unblocked subpath modules like fs/promises, enabling arbitrary write access to the host filesystem.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-269
  • Attack Vector: Network
  • CVSS v3.1: 8.5
  • EPSS Score: 0.00384
  • Exploit Status: PoC
  • CISA KEV Status: Not Listed

Affected Systems

  • vm2 Node.js sandboxing library
  • vm2: <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: 59d35f6

Fix builtin-module denylist bypass in NodeVM

Exploit Details

Mitigation Strategies

  • Upgrade the vm2 package to version 3.11.7 or higher.
  • Manually list all subpath modules in the deny list of NodeVM if upgrading is not immediately possible.
  • Migrate away from the deprecated vm2 library to stronger isolation runtimes such as WebAssembly or Docker containers.

Remediation Steps:

  1. Run 'npm install vm2@3.11.7' to apply the update.
  2. Audit existing NodeVM initialization configurations to ensure negative rules include both parent and subpath modules.
  3. Validate the sandbox constraints using automated test suites.

References


Read the full report for CVE-2026-92958 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)