A critical vulnerability affecting vm2 CVE-2026-92948 with a CVSS score of 9.9 affects vm2 in Node.js environments that allow sandbox escape via node.run execArgv, enabling arbitrary JavaScript execution outside the NodeVM sandbox. The flaw arises from a combination of builtin admission, generic host passthrough, and prefix normalization, allowing an attacker to execute untrusted JavaScript and escape the sandbox, resulting in complete confidentiality, integrity, and availability impact for the hosting service. An attacker who intentionally executes untrusted JavaScript can exploit this vulnerability to access the host user's filesystem, environment, network, and process-execution permissions, leading to a significant business impact.
We recommend you to update vm2 to version 3.12.2 or later.[/subscribe_to_unlock_form]
A critical vulnerability affecting vm2 CVE-2026-92948 with a CVSS score of 9.9 affects vm2 in Node.js environments that allow sandbox escape via node.run execArgv, enabling arbitrary JavaScript execution outside the NodeVM sandbox. The flaw arises from a combination of builtin admission, generic host passthrough, and prefix normalization, allowing an attacker to execute untrusted JavaScript and escape the sandbox, resulting in complete confidentiality, integrity, and availability impact for the hosting service. An attacker who intentionally executes untrusted JavaScript can exploit this vulnerability to access the host user's filesystem, environment, network, and process-execution permissions, leading to a significant business impact.
We recommend you to update vm2 to version 3.12.2 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]