Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.3 Node.js & npm GHSA-647f-g98j-qq25 CVE-2026-92937 GHSA-98xx-8mx4-x7cm CVE-2026-92941

vm2 Sandbox: Eight New Vulnerabilities Allow Host Process Escape and RCE

vm2 3.11.7 fixes eight separate sandbox-escape and isolation-bypass vulnerabilities, several allowing arbitrary code execution in the host Node.js process. All affected versions up to and including 3.11.6 should be upgraded immediately.

AI summary

The vm2 npm package, used to run untrusted JavaScript in an isolated sandbox within Node.js applications, has eight newly disclosed vulnerabilities affecting versions up to and including 3.11.6. The issues range from incomplete fixes of prior sandbox-escape bugs to newly discovered bypasses involving Promise handling, TLS trust store manipulation, HTTPS credential theft, native code loading via the crypto module, and a CLI tool that provides no sandbox isolation at all. All eight issues are fixed in vm2 3.11.7. Several of these vulnerabilities carry a maximum or near-maximum CVSS score and allow full compromise of the host Node.js process from code running inside what is supposed to be an isolated sandbox.

Multiple sandbox-escape vulnerabilities disclosed in vm2

Eight distinct vulnerabilities were disclosed for the vm2 sandboxing library, all affecting versions up to and including 3.11.6 and fixed in 3.11.7: - CVE-2026-92937 (GHSA-647f-g98j-qq25, CVSS 10): An incomplete fix for a prior sandbox-escape issue. The bridge code that sanitises rejected host Promise values only checks the direct call target, so registering a rejection handler via Function.prototype.call/.apply indirection bypasses sanitisation and can expose a host object (e.g. the process object) to sandbox code, enabling arbitrary command execution with host privileges. - CVE-2026-92935 (GHSA-8hr7-r645-pc6w, CVSS 9.5): The NodeVM constructor's nesting guard incorrectly treats an array-shaped `require` option as a valid configuration, allowing an attacker to require the host vm2 module itself and create an inner NodeVM with an attacker-chosen builtin allowlist (such as child_process), escaping the sandbox entirely. - CVE-2026-92944 (GHSA-27g9-p43v-cw3v, CVSS 9.3): On Node.js 26, Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale V8 protector mechanism, allowing an attacker-controlled Promise to reach the host Function constructor and process object. - CVE-2026-92939 (GHSA-46pr-c5wc-xffx, CVSS 9.4): When the crypto builtin is allowed in a NodeVM sandbox, sandboxed code can call crypto.setEngine() with a path to an attacker-supplied native library, causing the host OS loader to execute native code in the host process before engine validation occurs. - CVE-2026-92950 (GHSA-jxxv-8r27-vm4p, CVSS 9.3): The vm2 CLI tool provides no real sandbox isolation. A malicious script can use require(__filename) to re-execute itself in the host realm, gaining access to host modules such as fs and child_process. - CVE-2026-92952 (GHSA-jf8q-945g-9q4c, CVSS 8.9): An incomplete fix for earlier symbol-filtering issues. The filters omit two registered Node.js stream symbols (nodejs.stream.disturbed and nodejs.stream.errored) exposed on host WebStream prototypes on newer Node.js releases, letting sandbox code corrupt host-visible stream state. This issue does not provide host code execution. - CVE-2026-92941 (GHSA-98xx-8mx4-x7cm, CVSS 10): A NodeVM sandbox with access to the tls and url builtins can call tls.setDefaultCACertificates() to replace the host process's trusted certificate authorities, enabling man-in-the-middle acceptance of attacker-controlled TLS certificates by other host HTTPS clients. - CVE-2026-92940 (GHSA-h85j-hv3c-qfgq, CVSS 10): When a NodeVM is configured to allow require('https'), sandbox code can register a listener on the host's shared https.globalAgent connection pool and intercept live host HTTP requests, reading Authorization headers and response bodies, and replaying stolen credentials.

Root causes: incomplete sandbox boundaries and leaked host objects

The vulnerabilities share a common theme: vm2's sandbox relies on proxies, allowlists, and identity checks to separate sandboxed code from the host Node.js realm, but several of these controls have gaps. Some are incomplete fixes for previously patched issues (CVE-2026-92937 and CVE-2026-92952), where the original fix handled the direct exploitation path but missed an equivalent indirect path (function indirection, or additional stream symbols). Others stem from builtin modules (crypto, tls, https) being exposed to the sandbox with insufficient restriction on the operations they permit, allowing sandboxed code to reach host-level state or trigger native code loading. One issue (CVE-2026-92935) is a logic error in option validation that misclassifies an array as a valid configuration object. The CLI issue (CVE-2026-92950) reflects that the vm2 command-line tool was never designed to provide the same isolation guarantees as the library's sandbox API.

Why this matters

vm2 is designed specifically to run untrusted JavaScript safely. These vulnerabilities undermine that core guarantee: several allow code running inside the sandbox to execute arbitrary commands with the full privileges of the host Node.js process, or to steal credentials and manipulate TLS trust decisions that affect the host application as a whole. Four of the eight issues (CVE-2026-92937, CVE-2026-92941, CVE-2026-92940, and partially CVE-2026-92935) carry the maximum or near-maximum CVSS base score of 10 or 9.5, reflecting network-exploitable, low-complexity paths to full compromise. Applications that embed vm2 to execute plugins, user scripts, or other untrusted code are directly exposed if attackers can supply code that runs inside the sandbox.

Who is affected

Any application that embeds the vm2 package (npm ecosystem) to run untrusted or semi-trusted JavaScript — for example plugin systems, code-execution services, or NodeVM-based external module loading — is affected if running a version up to and including 3.11.6. Exploitability for individual issues depends on which builtins and sandbox options the embedder has enabled: crypto exposure is needed for CVE-2026-92939, tls and url exposure for CVE-2026-92941, https exposure for CVE-2026-92940, nesting plus an array-shaped require option for CVE-2026-92935, and a host-realm Promise bridged into the sandbox for CVE-2026-92937. CVE-2026-92950 affects users of the vm2 CLI tool specifically, and CVE-2026-92952 requires exposure of host WebStream objects and the stream/web module.

Affected versions

Affected version ranges vary by issue: CVE-2026-92937 affects version 3.11.6; CVE-2026-92941, CVE-2026-92940, and CVE-2026-92939 affect versions 3.11.3 through 3.11.6; CVE-2026-92935 and CVE-2026-92952 affect versions 3.11.4 through 3.11.6; CVE-2026-92944 affects versions 3.10.2 through 3.11.6; and CVE-2026-92950 affects all versions up to and including 3.11.6. All eight issues are resolved in vm2 3.11.7.

Fixes and mitigation

All eight vulnerabilities are fixed in vm2 version 3.11.7. Organisations should upgrade to this version as soon as possible. Where immediate upgrade is not possible, reducing the set of builtin modules (crypto, tls, url, https) and sandbox options (nesting, require) exposed to NodeVM instances can reduce exposure to several individual issues, though this does not address every root cause (in particular the Promise-sanitisation bypass in CVE-2026-92937 and the Node.js 26 V8 protector issue in CVE-2026-92944).

Recommended action

Upgrade vm2 to version 3.11.7 in all applications and services that depend on it, prioritising systems that expose crypto, tls, https, or url builtins, or that allow nesting with custom require configurations, or that use the vm2 CLI tool. After upgrading, review which builtin modules and sandbox options are actually necessary for your use case and disable any that are not required, as defense in depth against future sandbox-boundary issues.

PatchBriefing score

6.3 / 10 · Medium

Official CVSS: 10.0

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The patchwire scores for these issues range from 5.1 to 6.3, driven primarily by CVSS base scores between 8.9 and 10. Several issues (CVE-2026-92937, CVE-2026-92941, CVE-2026-92940, CVE-2026-92935, CVE-2026-92952) are flagged as unauthenticated and remotely reachable with no user interaction required, contributing modest additional score. None of the eight vulnerabilities are currently listed as known exploited, have confirmed public exploit code, or appear in ransomware campaigns, which keeps the overall patchwire scores in the moderate range despite high CVSS base scores. A fix is available for all issues (vm2 3.11.7), which also limits score contribution from the 'no fix available' factor.

Affected versions

vm2 = 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.11.3, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.11.3, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.11.4, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.10.2, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.11.3, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 >= 3.11.4, <= 3.11.6
vulnerable
≥ 3.11.7
patched
vm2 <= 3.11.6
vulnerable
≥ 3.11.7
patched

Reported fixes

All eight vulnerabilities are fixed in vm2 version 3.11.7. Organisations should upgrade to this version as soon as possible. Where immediate upgrade is not possible, reducing the set of builtin modules (crypto, tls, url, https) and sandbox options (nesting, require) exposed to NodeVM instances can reduce exposure to several individual issues, though this does not address every root cause (in particular the Promise-sanitisation bypass in CVE-2026-92937 and the Node.js 26 V8 protector issue in CVE-2026-92944).

How this was built

16 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
vm2 Sandbox: Eight New Vulnerabilities Allow Host Process Escape and RCE
1 article · 16 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email