← Back to search

CVE-2026-93605

10 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-21

AI risk analysis

Summary
This vulnerability allows attackers to escape the sandbox and execute arbitrary commands on the host system by exploiting the DANGEROUS_BUILTINS denylist in vm2 NodeVM versions before 3.12.1.
Exploitability
Exploitation is relatively straightforward if the attacker can influence the configuration to include child_process in the allowed builtins.
Blast radius
If exploited, this can lead to complete compromise of the host system, including data theft, system damage, and further lateral movement.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 NodeVM 3.12.1 or later.
rcevm2nodejssandbox-escapearbitrary-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-693

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.