PT-2026-95384 · Npm · Vm2
CVE-2026-93605
·
Published
2026-09-03
·
Updated
2026-09-19
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
vm2 NodeVM versions prior to 3.12.1
Description
A sandbox escape exists because the
DANGEROUS BUILTINS denylist fails to include child process, even though other modules capable of spawning host processes are blocked. This allows attackers to require child process and execute arbitrary commands on the host system if NodeVM is configured with builtin:['*'] or if child process is explicitly allowed.Recommendations
Update vm2 NodeVM to version 3.12.1 or later.
Exploit
Fix
RCE
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2