CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-92950

CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 2, 2026·5 min read·2 visits

Executive Summary (TL;DR)

A design flaw in the vm2 CLI tool permits sandboxed code to load local files in the host execution realm, resulting in a complete sandbox escape and unauthenticated arbitrary command execution.

CVE-2026-92950 (GHSA-jxxv-8r27-vm4p) is a critical sandbox escape vulnerability in the command-line interface of the vm2 library prior to version 3.11.7. The flaw allows untrusted scripts to bypass sandbox constraints and execute arbitrary system commands with the privileges of the host process by exploiting insecure default configurations of the module resolver.

Vulnerability Overview

The vm2 library is a widely deployed Node.js library used to execute untrusted code in a sandboxed, isolated execution environment. To ensure isolation, vm2 wraps JavaScript execution frames using proxy objects and custom resolvers to intercept sensitive API calls. This sandboxing is critical for applications that process untrusted user-supplied code, such as online code editors or automated execution systems.

Prior to version 3.11.7, the global command-line interface tool supplied with vm2 contains a significant security configuration flaw. When running a targeted script through the CLI execution path, the runner instantiates an instance of the NodeVM engine with permissive external module options. This module resolution configuration is vulnerable to a sandbox escape that grants complete shell access to the host environment.

This specific bug class maps to CWE-453 (Insecure Default Variable Initialization). By executing arbitrary commands with the privileges of the executing process, an attacker can fully compromise the underlying host operating system. The vulnerability presents an immediate path to local privilege escalation or container escape if the CLI tool runs within a containerized environment.

Root Cause Analysis

The root cause of CVE-2026-92950 lies in how the vm2 command-line utility instantiates the sandboxed NodeVM instance in lib/cli.js. The CLI tool sets the require.external flag to true to allow sandboxed modules to import external dependencies. However, it fails to define the require.root property and leaves require.context unconfigured, causing it to fall back to the default 'host' evaluation context.

Within the vm2 library, the class CustomResolver (implemented in lib/resolver-compat.js) manages permissions for imported file paths. The resolution logic evaluates paths using a helper function called isPathAllowed. When require.root is undefined, the internal rootPaths array is also initialized as undefined, causing the resolver to permit any absolute or relative path without restriction.

Simultaneously, the 'host' evaluation context dictates that permitted modules must be loaded using the host process's native require() function rather than being evaluated within the sandbox context. Under these specific conditions, the resolver intercepts module queries and safely resolves the absolute path of the target script, but then hands the path over to Node's native module loader. Because native execution happens entirely in the host realm, the sandbox execution boundary is bypassed.

Code-Level Analysis

A review of the vulnerable implementation in lib/cli.js demonstrates the omission of restricting properties during the VM setup. The initialization configures external: true without constraining the root path or context:

// Vulnerable configuration in lib/cli.js (Pre-3.11.7)
NodeVM.file(path, {
    verbose: true,
    require: {
        external: true
    }
});

In the patch released in version 3.11.7, the developers explicitly declared the root property as the parent directory of the script and set the execution context to 'sandbox' to block native module execution. The fix constrains imports and compiles them inside the safe sandbox wrapper:

// Patched configuration in lib/cli.js (v3.11.7)
NodeVM.file(path, {
    verbose: true,
    require: {
        external: true,
        // Explicitly set the root boundary to the target directory
        root: pa.dirname(path),
        // Enforce script execution inside the sandbox realm
        context: 'sandbox'
    }
});

Furthermore, defense-in-depth measures were introduced in the resolution module to prevent nested escape routes. The update introduces the isVm2SelfRequire helper to block sandboxed scripts from loading vm2 itself. Without this block, an attacker could load the library from disk and generate unrestricted nested engines to execute commands on the host.

Exploitation Methodology

Exploitation of CVE-2026-92950 relies on a nested-import technique often referred to as a "self-require" primitive. An attacker crafts a malicious JavaScript file designed to run under dual execution phases. During the initial execution phase, the script runs within the sandboxed environment where calls to high-privilege built-in modules like fs or child_process fail.

When these calls fail and throw exceptions, the catch block intercepts the error and executes the escape payload. The script triggers a call to require(__filename), pointing directly back to its own file path on the host filesystem. Because the module root boundary is unrestricted and the resolution context is 'host', the custom resolver authorizes the native Node.js engine to load the file.

Upon the second execution phase, Node.js resolves and runs the script from the top using the host's native environment. This grants the script unrestricted access to the host's global context. The second execution successfully accesses the native fs and child_process modules, allowing arbitrary shell command execution with the privileges of the host process.

Remediation and Defensive Measures

To completely address the vulnerability, administrators must upgrade the vm2 dependency to version 3.11.7 or higher. Organizations utilizing the CLI tool globally should execute updates to purge vulnerable versions from their global NPM configurations. It is important to note that the vm2 project has been officially deprecated by its maintainers due to structural design limitations within single-process Node.js sandbox systems.

For applications that instantiate NodeVM dynamically in code, developer teams must implement robust configuration policies. Never enable require.external without specifying a restricted require.root path. Enforcing context: 'sandbox' is also required to prevent the loading of modules inside the native host execution frame.

If immediate patching or replacement is not possible, security teams must deploy detection rules to identify exploit attempts. Monitor process creation events originating from Node.js applications that execute untrusted code. Deploying system-level controls like AppArmor or SELinux can block unauthorized system calls if an attacker successfully escapes the runtime sandbox.

Official Patches

patriksimekFix commit restricting resolution pathways in lib/cli.js
patriksimekOfficial GitHub Release page for fixed version 3.11.7

Fix Analysis (1)

Technical Appendix

CVSS Score
9.3/ 10
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS Probability
0.20%
Top 91% most exploited

Affected Systems

vm2 CLI (npm package)

Affected Versions Detail

Product
Affected Versions
Fixed Version
vm2
patriksimek
< 3.11.73.11.7
AttributeDetail
CWE IDCWE-453 (Insecure Default Variable Initialization)
Attack VectorLocal
CVSS v4.0 Score9.3 (Critical)
EPSS Score0.00197 (8.53rd Percentile)
Exploit StatusProof-of-Concept Publicly Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1211Exploitation for Defense Evasion
Defense Evasion
T1059.003Command and Scripting Interpreter: JavaScript
Execution
CWE-453
Insecure Default Variable Initialization

The vm2 CLI tool initializes the sandboxed context with an insecure configuration, omitting the root boundary and evaluation context rules, enabling module resolution inside the host realm.

Known Exploits & Detection

GitHub Security AdvisoryGHSA advisory describing the insecure default options and reproduction payload.

Vulnerability Timeline

Vulnerability discovered, addressed and commit 903017c8a1eae9aba947ec854468b48155e79f86 applied
2026-08-22
Patched version 3.11.7 published
2026-08-22
CVE-2026-92950 record officially published
2026-09-17

References & Sources

  • [1]GitHub Security Advisory
  • [2]VulnCheck Security Advisory
  • [3]CVE Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-92948
9.9

CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

CVE-2026-92948 is a critical sandbox escape vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6 when executed on Node.js 24 and newer. The vulnerability allows an attacker to bypass built-in module blocking defenses by double-prefixing a restricted module name (such as node:node:test). This permits the loading of the node:test module, whose test runner execution can be leveraged to execute arbitrary shell commands outside the VM sandbox.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 2 hours ago•CVE-2026-92952
8.9

CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak

A high-severity sandbox escape and state corruption vulnerability exists in the vm2 library (versions 3.11.4 through 3.11.6). The vulnerability is caused by an incomplete blocklist of Node.js-internal registered symbols crossing the sandbox-host bridge boundary. Specifically, the filters in `lib/setup-sandbox.js` and write traps in `lib/bridge.js` omitted the symbols `nodejs.stream.disturbed` and `nodejs.stream.errored`, allowing untrusted code within the sandbox to corrupt host-realm stream state checks.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 3 hours ago•CVE-2026-73607
5.8

CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure

An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.

Amit Schendel
Amit Schendel
6 views•7 min read
•about 4 hours ago•CVE-2026-73609
5.8

CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint

An information disclosure vulnerability (CWE-862) in the SiYuan Note platform before version v3.7.4 allows anonymous or unprivileged readers to obtain a complete list of bookmark labels globally across all workspaces and notebooks by querying the `/api/attr/getBookmarkLabels` API endpoint.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•GHSA-9CQF-HHRQ-7V45
5.3

Missing publish-access check on getAttributeViewSearchTarget endpoint exposes database row content to unauthorized readers

An authorization bypass and information leakage vulnerability exists in the SiYuan database module. Unauthenticated users can query the getAttributeViewSearchTarget API endpoint using target block identifiers to extract private content.

Alon Barad
Alon Barad
6 views•5 min read
•about 7 hours ago•CVE-2026-76504
9.8

CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager

CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.

Amit Schendel
Amit Schendel
13 views•7 min read