CVE-2026-92957: vm2 sandbox escape via node: prefix bypass
A critical flaw in vm2 up to 3.11.6 (CVE-2026-92957, CVSS 9.9) lets sandboxed code bypass negative builtin deny rules written with the node: prefix, import the host child_process module and run arbitrary commands. Fixed in vm2 3.11.7; a proof of concept exists.
- CVSS 9.9; vm2 3.11.6 and earlier affected
- Bypass via node:-prefixed negative deny tokens in wildcard policy
- Allows importing child_process and host command execution
- Fixed in vm2 3.11.7; PoC available
Read next
Security