PT-2026-95384 · Npm · Vm2

CVE-2026-93605

·

Published

2026-09-03

·

Updated

2026-09-19

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions vm2 NodeVM versions prior to 3.12.1
Description A sandbox escape exists because the DANGEROUS BUILTINS denylist fails to include child process, even though other modules capable of spawning host processes are blocked. This allows attackers to require child process and execute arbitrary commands on the host system if NodeVM is configured with builtin:['*'] or if child process is explicitly allowed.
Recommendations Update vm2 NodeVM to version 3.12.1 or later.

Exploit

Fix

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14924
CVE-2026-93605
GHSA-PQ68-RVW4-XP4R

Affected Products

Vm2