PT-2026-94328 · Npm · Vm2

·

CVE-2026-92957

·

Published

2026-08-25

·

Updated

2026-09-26

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.7
Description NodeVM fails to normalize node:-prefixed builtin specifiers when evaluating negative (deny) entries in a wildcard require policy. While the node: prefix is stripped during resolution, negative wildcard entries are matched using exact string comparison against canonical builtin names. Consequently, a policy intended to deny a module using the node: prefix fails to block the canonical version. This allows sandboxed code to access the host child process builtin via require('child process') or require('node:child process'), providing access to process-spawning APIs such as execSync() and spawn(), which enables host command execution.
Recommendations Update to version 3.11.7.

Exploit

Fix

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15021
CVE-2026-92957
GHSA-8686-VHFX-7R3J

Affected Products

Vm2