CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass
Vulnerability ID: CVE-2026-92957
CVSS Score: 9.9
Published: 2026-10-01
A vulnerability in the NodeVM component of the vm2 sandbox package through version 3.11.6 allows sandboxed code to bypass security policies restricting access to built-in modules. When a wildcard require policy is configured with negative deny entries using the 'node:' prefix (e.g., '-node:child_process'), the parser fails to recognize the exemption due to exact string comparison. As a result, the unmitigated module is registered, allowing sandboxed code to import the host child_process module and execute arbitrary system commands.
TL;DR
vm2 fails to normalize the 'node:' prefix in negative builtin policy entries, allowing sandboxed code to load disallowed modules like 'child_process' and achieve remote code execution on the host.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-269
- Attack Vector: Network
- CVSS v3.1 Score: 9.9 (Critical)
- CVSS v4.0 Score: 9.4 (Critical)
- EPSS Score: 0.00537 (43.14th percentile)
- Exploit Maturity: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- vm2 sandbox environments running version 3.11.6 or earlier
-
vm2: <= 3.11.6 (Fixed in:
3.11.7)
Code Analysis
Commit: b0f5066
fix(GHSA-8686-vhfx-7r3j): normalize the node: prefix on negative builtin deny tokens
@@ -12,3 +12,9 @@\n \t\t\t\tconst name = BUILTIN_MODULES[i];\n-\t\t\t\tif (builtins.indexOf(`-${name}`) === -1) {\n+\t\t\t\t// SECURITY (GHSA-8686-vhfx-7r3j): a negative deny token may be\n+\t\t\t\t// spelled with the `node:` URL prefix (`-node:child_process`),\n+\t\t\t\t// matching how `require()` accepts `node:`-prefixed specifiers.\n+\t\t\t\t// The exact-string match only recognized `-child_process`, so the\n+\t\t\t\t// `node:` spelling was a silent no-op and left the real host\n+\t\t\t\t// module exposed under `builtin: ['*']`. Match BOTH spellings.\n+\t\t\t\tif (builtins.indexOf(`-${name}`) === -1 && builtins.indexOf(`-node:${name}`) === -1) {\n \t\t\t\t\taddDefaultBuiltin(res, name, hostRequire);\n
Mitigation Strategies
- Upgrade the vm2 package to version 3.11.7 or later to resolve the prefix normalization error.
- Avoid wildcard configurations with negative exclusions. Instead, explicitly define a strict allowlist containing only the minimal set of required modules.
- Migrate existing sandboxed execution flows away from vm2 to alternative isolation boundaries such as WebAssembly runtimes or containerized processes.
Remediation Steps:
- Identify all projects and configurations utilizing the vm2 package.
- Review configuration files initializing NodeVM, locating any occurrences of wildcard require policies containing negative deny tokens (e.g., 'builtin: ["*", "-node:..."]').
- Update package.json dependencies to target 'vm2': '^3.11.7'. Run npm install or yarn install to apply the patch.
- If upgrading is not immediately possible, rewrite the NodeVM options block to explicitly allow only specific safe built-in libraries (e.g., builtin: ['path', 'url']) and avoid using wildcard rules combined with exemptions.
References
- GitHub Security Advisory GHSA-8686-vhfx-7r3j
- VulnCheck Advisory for vm2 Node Prefix Bypass
- CVE Record JSON Data
- NVD CVE-2026-92957 Detail
- CVE.org CVE-2026-92957 Record
- Fix Commit b0f5066
Read the full report for CVE-2026-92957 on our website for more details including interactive diagrams and full exploit analysis.












