Junglewise Threat Intelligence

CVE-2026-92960: vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host

CVE-2026-92960 · Severity: critical · CVSS 10 · Published 2026-09-17

Technologies: vm2 (npm). Vendors: npm.

Executive brief

vm2 is a JavaScript sandboxing library used to safely execute untrusted code in isolation. When configured with the documented "full builtins" pattern (builtin: ['*']), the sandbox incorrectly exposes the os and dns Node.js modules, allowing an attacker to read sensitive host information (network topology, user credentials, system telemetry) and perform DNS hijacking that affects the entire host process, defeating the sandbox isolation guarantee.

Technical details

This vulnerability is a sandbox escape in vm2's NodeVM due to incomplete module blocklisting. The os and dns builtins are not included in the DANGEROUS_BUILTINS set despite satisfying the same criteria established in GHSA-9g8x-92q2-p28f: they expose and mutate global host-process state that cannot be localized by vm.readonly() proxies. Attack requires NodeVM configuration with builtin: ['*'] (the documented recommended pattern) and no manual -os/-dns exclusions. An attacker controlling sandbox code can call os.userInfo(), os.networkInterfaces(), os.hostname() to exfiltrate host deployment details, and invoke dns.setServers() to perform process-wide DNS hijacking affecting all host outbound network calls. No authentication or user interaction is required. The fix adds os and dns to DANGEROUS_BUILTINS in patched version 3.11.6.

Affected products

  • vm2 vm2 <= 3.11.5

Timeline

  • 2026-08-17: disclosed
  • 2026-08-14: patched: Version 3.11.6

References

Related threats