CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9
A critical sandbox escape, CVE-2026-92948, affects vm2 versions 3.9.6 through 3.11.6 on Node.js 24 and newer. Double-prefixing node:node:test bypasses builtin module blocking and allows arbitrary host command execution. It is fixed in vm2 3.11.7.
- Affects vm2 3.9.6–3.11.6 running on Node.js 24+
- CVSS 9.9 with a public proof-of-concept exploit
- Fixed in vm2 3.11.7 via recursive prefix validation
- Remove '*' and node:test from the builtin allowlist
Read next
Security