CVE-2026-92951: vm2 sandbox escape via external package allowlist bypass
A vulnerability tracked as CVE-2026-92951 with a CVSS score of 9.9 was found in the vm2 library before version 3.11.7. Unanchored substring matching and missing directory traversal filtering let sandboxed code load and execute arbitrary host packages with host privileges.
- CVSS score is 9.9, exploit status is proof of concept
- vm2 versions below 3.11.7 are affected, fixed in 3.11.7
- Attack vector is network and leads to host code execution
- Upgrade to 3.11.7 or move to isolated-vm and containers
Read next
Security