Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. vm2
  4. ›
  5. CVE-2026-92948

CVE-2026-92948: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape

October 1, 2026

On Node.js 24 and newer, vm2 can expose the host node:test module to sandboxed NodeVM code when the embedder explicitly allows the node:test builtin. Sandbox code can reach that module through require('node:node:test') and call run() with attacker-controlled execArgv.

node:test.run() starts a separate Node process for process-isolated test execution and forwards the supplied execArgv values to that process. Supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process, outside the NodeVM sandbox.

The PoC confirms that direct sandbox imports of fs, child_process, module, and process remain denied before the spawned process imports host fs and writes a harmless marker.

References

  • github.com/advisories/GHSA-qhwx-74w5-xhxq
  • github.com/patriksimek/vm2/commit/415339f698f0d52d3c5ad358b12b79c8072d5b4b
  • github.com/patriksimek/vm2/releases/tag/v3.11.7
  • github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq
  • nvd.nist.gov/vuln/detail/CVE-2026-92948
  • www.vulncheck.com/advisories/vm2-3.9.6-through-3.11.5-sandbox-escape-via-node-test

Code Behaviors & Features

Detect and mitigate CVE-2026-92948 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.9.6 before 3.11.7

Fixed versions

  • 3.11.7

Solution

Upgrade to version 3.11.7 or above.

Impact 9.9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-693: Protection Mechanism Failure

Source file

npm/vm2/CVE-2026-92948.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 02 Oct 2026 12:17:07 +0000.