Skip to content
CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

Dev.To • October 2, 2026

CVE-2026-92948 is a critical sandbox escape vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6 when executed on Node.js 24 and newer. The vulnerability allows an attacker to bypass built-in module blocking defenses by double-prefixing a restricted module name (such as node:node:test). This permits the loading of the node:test module, whose test runner execution can be leveraged to execute arbitrary shell commands outside the VM sandbox.

A critical sandbox escape in vm2 (versions >=3.9.6 to = 3.9.6, <= 3.11.6 (Fixed in: 3.11.7 )

Fix GHSA-qhwx-74w5-xhxq: sanitize input and block dangerous builtins recursively

GitHub Security Advisory : Vulnerability disclosure detailing the node:test sandbox escape exploit vector.

Mitigation Strategies

Upgrade vm2 to version 3.11.7 or later to apply recursive prefix validation.

Explicitly remove wildcard ('*') and 'node:test' from the VM's builtin allowlist.

Migrate to isolated-vm to use secure V8 isolate-based boundaries instead of vm2.

Execute untrusted code within secure container environments (e.g., Docker, gVisor) to limit host system exposure.

Identify all microservices and dependencies utilizing the vm2 npm package.

Update package.json to specify vm2 version 3.11.7 or newer, then execute 'npm install'.

Inspect NodeVM configurations to ensure the 'builtin' array does not contain '*' or 'node:test'.

Plan the deprecation of vm2 in favor of a containerized execution model or isolated-vm.

vm2 v3.11.7 Release Notes

NVD CVE-2026-92948 Detail

Read the full report for CVE-2026-92948 on our website for more details including interactive diagrams and full exploit analysis.

For further actions, you may consider blocking this person and/or reporting abuse

Extracted Entities

Attack Types (1)

Platforms (1)

Tools (2)

Vulnerabilities (1)