CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem
Vulnerability ID: CVE-2026-92958
CVSS Score: 8.5
Published: 2026-10-01
CVE-2026-92958 is a high-severity sandbox escape and denylist bypass vulnerability within the NodeVM subsystem of the vm2 sandboxing library. When configuring wildcards with negative deny entries, exact-string matches fail to block subpaths like fs/promises. Sandboxed code can import these subpaths to bypass isolation and execute arbitrary filesystem operations on the host.
TL;DR
A denylist bypass vulnerability in vm2 <= 3.11.6 allows sandboxed code to bypass security rules by importing unblocked subpath modules like fs/promises, enabling arbitrary write access to the host filesystem.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-269
- Attack Vector: Network
- CVSS v3.1: 8.5
- EPSS Score: 0.00384
- Exploit Status: PoC
- CISA KEV Status: Not Listed
Affected Systems
- vm2 Node.js sandboxing library
-
vm2: <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: 59d35f6
Fix builtin-module denylist bypass in NodeVM
Exploit Details
- GitHub Security Advisory: No description
Mitigation Strategies
- Upgrade the vm2 package to version 3.11.7 or higher.
- Manually list all subpath modules in the deny list of NodeVM if upgrading is not immediately possible.
- Migrate away from the deprecated vm2 library to stronger isolation runtimes such as WebAssembly or Docker containers.
Remediation Steps:
- Run 'npm install vm2@3.11.7' to apply the update.
- Audit existing NodeVM initialization configurations to ensure negative rules include both parent and subpath modules.
- Validate the sandbox constraints using automated test suites.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-6rh5-qq4q-97xh
- https://github.com/patriksimek/vm2/commit/59d35f68e52a9bd229a8a72bcd9274bd4cec2bc5
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-denylist-bypass-via-fs-promises
- https://www.cve.org/CVERecord?id=CVE-2026-92958
- https://nvd.nist.gov/vuln/detail/CVE-2026-92958
Read the full report for CVE-2026-92958 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)