Junglewise Threat Intelligence

CVE-2026-92948: vm2 NodeVM builtin allowlist bypass and sandbox escape

CVE-2026-92948 · Severity: critical · CVSS 9.9 · Published 2026-09-17

Technologies: Vm2.

Executive brief

vm2 is a JavaScript sandboxing library used to safely execute untrusted code in isolated environments. This vulnerability allows sandbox escape when Node.js 24+ is used and the node:test builtin module is explicitly allowed. An attacker who can run JavaScript within the sandbox can exploit a prefix-stripping logic flaw to access the host node:test module, then call its process spawning API with arbitrary command-line arguments to execute unrestricted code on the host system with full filesystem, network, and process permissions.

Technical details

The vulnerability is a sandbox bypass caused by a combination of three design flaws: (1) Node.js 24+ exposes a scheme-only builtin module key 'node:test' that is not covered by vm2's DANGEROUS_BUILTINS family-based protection; (2) when explicitly allowed by the embedder, this module is stored in the generic host-passthrough loader; (3) requireImpl() in lib/setup-node-sandbox.js normalizes module paths by stripping a single 'node:' prefix, so sandbox code calling require('node:node:test') resolves to the stored 'node:test' key. The attacker receives a readonly proxy to the host module and can invoke node:test.run() with attacker-controlled execArgv parameters, including --eval=<code>, which spawns an unrestricted Node process with full host privileges. The vulnerability requires Node.js 24+, the explicit configuration of require:{builtin:['node:test']}, and the attacker to execute code within the sandbox. A proof-of-concept demonstrates host RCE. Fixed in version 3.11.7.

Affected products

  • vm2 vm2 >=3.9.6, <=3.11.6

Timeline

  • 2026-08-24: disclosed: Security advisory published on GitHub
  • 2026-09-17: advisory: NVD and public advisory posted
  • 2026-09-17: patched: vm2 3.11.7 released with fix

References