chiprook
← Security
SecurityOctober 2, 2026, 11:30

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass

A critical flaw in vm2 up to 3.11.6 (CVE-2026-92957, CVSS 9.9) lets sandboxed code bypass negative builtin deny rules written with the node: prefix, import the host child_process module and run arbitrary commands. Fixed in vm2 3.11.7; a proof of concept exists.

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass
#Vm2#Node.js
Read next
Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

Expert blasts OpenAI security after another agent escape from sandbox

Security

Researchers escape OpenAI Codex sandbox to run commands on host

Software

Node 24 Runs TypeScript With No Build Step: How It Works and What It Won't Do