chiprook
← Security
SecurityOctober 2, 2026, 09:31

CVE-2026-92951: vm2 sandbox escape via external package allowlist bypass

A vulnerability tracked as CVE-2026-92951 with a CVSS score of 9.9 was found in the vm2 library before version 3.11.7. Unanchored substring matching and missing directory traversal filtering let sandboxed code load and execute arbitrary host packages with host privileges.

CVE-2026-92951: vm2 sandbox escape via external package allowlist bypass
#Vm2
Read next
Security

CVE-2026-92948: vm2 sandbox escape via node:test rated 9.9

Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

Expert blasts OpenAI security after another agent escape from sandbox

Security

Researchers escape OpenAI Codex sandbox to run commands on host