Critical Sandbox Escape Vulnerability in vm2 Library Disclosed
Article Content
- •CVE-2026-92948 allows remote code execution via vm2 library on Node.js 24+.
- •Affected versions are 3.9.6 to 3.11.6, with a critical CVSS score of 9.4.
- •Users must upgrade to vm2 version 3.11.7 or later to mitigate the vulnerability.
CVE-2026-92948 is a critical sandbox escape vulnerability affecting the vm2 library versions 3.9.6 to 3.11.6 on Node.js 24 and newer. This flaw allows attackers to bypass module blocking defenses by double-prefixing restricted module names, enabling the import of the 'node:test' module. Once imported, attackers can execute arbitrary shell commands outside the VM sandbox. The vulnerability was published on September 17, 2026, with a CVSS score of 9.4, indicating its critical nature. A patch was released in version 3.11.7 to address this issue. Users are advised to upgrade their vm2 library and implement additional mitigation strategies to secure their environments. The exploit vector poses a significant risk to systems utilizing the affected library, especially those running untrusted code.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (5)
Following this threat?
Track CVE-2026-92948 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of vm2 are affected?
What should I do to mitigate this vulnerability?
Is there any active exploitation reported?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…