Skip to content
Critical Sandbox Escape Vulnerability in vm2 Library Disclosed

Critical Sandbox Escape Vulnerability in vm2 Library Disclosed

First seen 2 Oct 2026, 12:13 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 13:09 UTC

CVE-2026-92948 is a critical sandbox escape vulnerability affecting the vm2 library versions 3.9.6 to 3.11.6 on Node.js 24 and newer. This flaw allows attackers to bypass module blocking defenses by double-prefixing restricted module names, enabling the import of the 'node:test' module. Once imported, attackers can execute arbitrary shell commands outside the VM sandbox. The vulnerability was published on September 17, 2026, with a CVSS score of 9.4, indicating its critical nature. A patch was released in version 3.11.7 to address this issue. Users are advised to upgrade their vm2 library and implement additional mitigation strategies to secure their environments. The exploit vector poses a significant risk to systems utilizing the affected library, especially those running untrusted code.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-92948 published
CVE-2026-92948 disclosed, detailing a critical sandbox escape vulnerability in vm2.
Dev.To
2026-10-02
Patch released for vm2
Version 3.11.7 of vm2 was released to address the critical vulnerability.
Dev.To

More articles in this cluster (5)

Following this threat?

Track CVE-2026-92948 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of vm2 are affected?
Versions 3.9.6 through 3.11.6 of the vm2 library are affected.
What should I do to mitigate this vulnerability?
Upgrade to vm2 version 3.11.7 or later, and implement additional security measures.
Is there any active exploitation reported?
No active exploitation has been reported; however, the vulnerability is critical and should be addressed immediately.