PT-2026-94321 · Npm · Vm2

·

CVE-2026-92950

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.7
Description A sandbox escape exists in the CLI tool that enables arbitrary code execution within the host Node.js process. An attacker can provide a malicious script file to the CLI that utilizes require( filename) to re-execute itself in the host realm. This action bypasses sandbox isolation, granting unauthorized access to host modules such as fs and child process.
Recommendations Update vm2 to version 3.11.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14943
CVE-2026-92950
GHSA-JXXV-8R27-VM4P

Affected Products

Vm2