{"id":"CVE-2026-92938","published":"2026-09-17T14:17:58.750","lastModified":"2026-09-19T03:17:18.443","description":"vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and the runtime strips only one 'node:' prefix, so a sandbox request for 'node:node:sqlite' resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process's privileges. The issue is fixed in vm2 3.11.7.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-693"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-remote-code-execution-via-node-sqlite","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows sandboxed code to execute arbitrary native code outside the sandbox with host process privileges by leveraging the Node.js sqlite module.","exploitability":"Exploitation requires the presence of the 'node:sqlite' module and the ability to load extensions, making it moderately complex but feasible with the right conditions.","blast_radius":"If exploited, the impact is severe as it grants arbitrary native code execution with the host process's privileges, potentially leading to full system compromise.","remediation":"Upgrade to vm2 3.11.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","native-code-execution","vm2"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:58:32.270Z"}}