PT-2026-94319 · Npm+1 · Vm2+1
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.9.6 through 3.11.6
Description
A NodeVM builtin allowlist bypass allows a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the
node:test builtin. On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by the family-based DANGEROUS BUILTINS protection and is stored in the generic host-passthrough loader. Because the requireImpl() function in lib/setup-node-sandbox.js strips a single node: prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values. Supplying --eval=<JavaScript> allows the execution of arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox.Recommendations
Update vm2 to version 3.11.7.
As a temporary workaround, avoid explicitly allowing the
node:test builtin in the require configuration.Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node.Js
Vm2