{"id":"CVE-2026-92948","published":"2026-09-17T14:18:00.310","lastModified":"2026-09-18T20:17:30.980","description":"vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-693"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-3.9.6-through-3.11.5-sandbox-escape-via-node-test","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a sandbox escape by bypassing vm2's allowlist, permitting execution of arbitrary JavaScript in a Node.js environment.","exploitability":"Exploitation requires explicit allowlisting of the 'node:test' module, which is uncommon but possible in certain configurations.","blast_radius":"If exploited, this could lead to full control over the host Node.js environment, including execution of arbitrary code.","remediation":"Upgrade to vm2 3.11.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","vm-bypass","nodejs","sandbox-escape"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:58:21.476Z"}}