PT-2026-94310 · Npm · Vm2

·

CVE-2026-92938

·

Published

2026-08-25

·

Updated

2026-09-19

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions 3.11.3 through 3.11.6
Description When the builtin: ['*'] configuration or explicit permission is granted, the host node:sqlite module is exposed to code running in NodeVM. Although the module is wrapped with vm.readonly() to prevent property assignment, host-authority callables remain reachable. A flaw in the resolver allows a request for node:node:sqlite to resolve to the node:sqlite entry because the runtime only strips one node: prefix. This enables sandboxed code to create an in-memory DatabaseSync with extension loading enabled and execute DatabaseSync.loadExtension() on a native library. Consequently, the library is loaded into the Node.js host process, allowing arbitrary native code execution with the privileges of the host process.
Recommendations Update to version 3.11.7.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14939
CVE-2026-92938
GHSA-6W8R-XXW2-G3HX

Affected Products

Vm2