PT-2026-94331 · Npm · Vm2

·

CVE-2026-92960

·

Published

2026-08-14

·

Updated

2026-10-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.6
Description When the builtin: ['*'] configuration is used, the software fails to restrict access to the os and dns built-in modules. This allows code running within the sandbox to access process-wide observability data and mutate the state of the host process. Specifically, an attacker can use os.userInfo() to read the host process owner's identity (UID, GID, username, and home directory) and os.networkInterfaces() to disclose the full host network topology, including IP and MAC addresses.
Furthermore, the sandbox can perform unauthorized writes to the host process. Using the os.setPriority() function, an attacker can change the host process priority. Most critically, by invoking the dns.setServers() function, an attacker can globally hijack the host process DNS resolver. This redirects all subsequent DNS queries made by the host—including outbound HTTP requests, telemetry, and package registry lookups—through a resolver controlled by the attacker, potentially leading to credential theft or supply chain attacks.
Recommendations Update vm2 to version 3.11.6 or later. As a temporary mitigation, avoid using the builtin: ['*'] configuration and instead explicitly list only the required built-in modules, ensuring that os and dns are excluded. Restrict the use of the os.setPriority() and dns.setServers() functions within the sandbox environment.

Exploit

Fix

Information Disclosure

Incorrect Permission

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15024
CVE-2026-92960
GHSA-M5W8-4GQ2-6F8X

Affected Products

Vm2