CVE-2026-92950: CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI
CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI Vulnerability ID: CVE-2026-92950 CVSS Score: 9.3 Published: 2026-10-01 CVE-2026-92950 (GHSA-jxxv-8r27-vm4p) is a critical sandbox escape vulnerability in the c
CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI
Vulnerability ID: CVE-2026-92950
CVSS Score: 9.3
Published: 2026-10-01
CVE-2026-92950 (GHSA-jxxv-8r27-vm4p) is a critical sandbox escape vulnerability in the command-line interface of the vm2 library prior to version 3.11.7. The flaw allows untrusted scripts to bypass sandbox constraints and execute arbitrary system commands with the privileges of the host process by exploiting insecure default configurations of the module resolver.
TL;DR
A design flaw in the vm2 CLI tool permits sandboxed code to load local files in the host execution realm, resulting in a complete sandbox escape and unauthenticated arbitrary command execution.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-453 (Insecure Default Variable Initialization)
- Attack Vector: Local
- CVSS v4.0 Score: 9.3 (Critical)
- EPSS Score: 0.00197 (8.53rd Percentile)
- Exploit Status: Proof-of-Concept Publicly Available
- KEV Status: Not Listed
Affected Systems
- vm2 CLI (npm package)
-
vm2: < 3.11.7 (Fixed in:
3.11.7)
Code Analysis
Commit: 903017c
Fix escape when running vm2 command line tool with require.root and require.context limits
Exploit Details
- GitHub Security Advisory: GHSA advisory describing the insecure default options and reproduction payload.
Mitigation Strategies
- Upgrade the vm2 library to version 3.11.7 or higher.
- Configure NodeVM instances with a explicitly specified require.root directory.
- Set require.context to 'sandbox' to enforce compilation boundaries within the VM.
- Migrate to runtime containerization or process-level isolation models.
Remediation Steps:
- Identify all global and local installations of the vm2 npm package.
- Run 'npm install [email protected]' or update package.json dependencies to target >=3.11.7.
- Audit custom NodeVM configuration code to verify that require.external is not used without require.root.
- Validate remediation by testing custom modules against the self-require exploit pattern.
References
Read the full report for CVE-2026-92950 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.