chiprook
← Security
SecurityOctober 2, 2026, 06:30

CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9

A critical sandbox escape, CVE-2026-92948, affects vm2 versions 3.9.6 through 3.11.6 on Node.js 24 and newer. Double-prefixing node:node:test bypasses builtin module blocking and allows arbitrary host command execution. It is fixed in vm2 3.11.7.

CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9
#Vm2#Node.js
Read next
Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

Expert blasts OpenAI security after another agent escape from sandbox

Security

Researchers escape OpenAI Codex sandbox to run commands on host

Software

Node 24 Runs TypeScript With No Build Step: How It Works and What It Won't Do