CVE-2026-92948: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
On Node.js 24 and newer, vm2 can expose the host node:test module to sandboxed NodeVM code when the embedder explicitly allows the node:test builtin. Sandbox code can reach that module through require('node:node:test') and call run() with attacker-controlled execArgv.
node:test.run() starts a separate Node process for process-isolated test execution and forwards the supplied execArgv values to that process. Supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process, outside the NodeVM sandbox.
The PoC confirms that direct sandbox imports of fs, child_process, module, and process remain denied before the spawned process imports host fs and writes a harmless marker.
References
- github.com/advisories/GHSA-qhwx-74w5-xhxq
- github.com/patriksimek/vm2/commit/415339f698f0d52d3c5ad358b12b79c8072d5b4b
- github.com/patriksimek/vm2/releases/tag/v3.11.7
- github.com/patriksimek/vm2/security/advisories/GHSA-qhwx-74w5-xhxq
- nvd.nist.gov/vuln/detail/CVE-2026-92948
- www.vulncheck.com/advisories/vm2-3.9.6-through-3.11.5-sandbox-escape-via-node-test
Code Behaviors & Features
Detect and mitigate CVE-2026-92948 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →