Junglewise Threat Intelligence

CVE-2026-93605: vm2 NodeVM sandbox escape via child_process denylist omission

CVE-2026-93605 · Severity: critical · CVSS 10 · Published 2026-09-18

Technologies: Patriksimek Vm2.

Executive brief

vm2 is a popular Node.js sandbox library used to safely execute untrusted code. A critical flaw in its security denylist allows attackers to access the child_process module and execute arbitrary system commands on the host computer with full privileges, completely bypassing the sandbox. Any application running untrusted user code through NodeVM with default or permissive settings is at immediate risk of complete system compromise.

Technical details

The vulnerability is a protection mechanism bypass in vm2's NodeVM sandbox (CWE-693). The DANGEROUS_BUILTINS denylist in lib/builtin.js is designed to block dangerous core modules (module, worker_threads, cluster, vm, repl, inspector, process, os, dns, v8, etc.) even when the sandbox requests builtin:['*'] or names them explicitly. However, child_process—the most direct host command-execution primitive—is omitted from this list. An attacker running sandboxed code can execute require('child_process').execSync() to run arbitrary shell commands on the host system. The vulnerability affects NodeVM when configured with require:{builtin:['*']}, the documented subtract pattern ['*', '-x', …], or explicit child_process allowance. Patched in version 3.12.1.

Affected products

  • Patriksimek vm2 <3.12.1

Timeline

  • 2026-09-03: advisory: GitHub Security Advisory GHSA-pq68-rvw4-xp4r published
  • 2026-09-18: disclosed: CVE-2026-93605 published on NVD
  • 2026-09-18: patched: Version 3.12.1 released with fix

References