vm2 NodeVM Sandbox Escape via node:test Builtin
The vm2 sandboxing library fails to properly secure the 'node:test' builtin module in Node.js 24+, allowing an attacker to escape the sandbox via a double-prefix require and execute arbitrary host code.
CVE search metadata
CVE search record: CVE-2026-92948. Severity: critical. CVSS: 9.9. EPSS: 0.65%. KEV: no. Product: vm2 (>= 3.9.6, <= 3.11.5). Brief: vm2 NodeVM Sandbox Escape via node:test Builtin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-vm2-node-test-bypass/
The vm2 library (versions 3.9.6 through 3.11.5) contains a critical sandbox escape vulnerability (CVE-2026-92948) when running on Node.js 24 or newer. The issue arises from a failure to correctly restrict the node:test builtin module. When an embedder explicitly allows node:test within a NodeVM configuration, sandboxed code can bypass the intended restrictions by requesting the module using a double prefix, require('node:node:test').
Normalization logic within vm2 resolves this to the node:test module, providing the sandbox with a readonly proxy to the host's test-runner. Because this proxy forwards calls to the host implementation without sufficient API validation, an attacker can invoke node:test.run() and supply arbitrary execArgv flags. By passing flags such as --eval, the attacker can spawn a child process that executes arbitrary JavaScript in an unrestricted host Node.js environment, effectively escaping the vm2 sandbox boundary.
Attack Chain
- Attacker identifies a target application utilizing
vm2withnode:testexplicitly enabled in therequire.builtinconfiguration. - Attacker injects malicious JavaScript into the
NodeVMsandbox environment. - Attacker invokes
require('node:node:test')within the sandbox to bypass existing builtin restriction filters. - The
vm2sandbox normalizes the path tonode:testand grants access to the host's test-runner module. - Attacker executes
node:test.run()within the sandbox, supplying a crafted object containing maliciousexecArgvparameters. - The
node:testrunner spawns a new Node.js child process using the attacker-suppliedexecArgvarguments. - The child process executes the attacker's payload (e.g.,
--eval='require("fs").writeFileSync(...)') outside the sandbox, granting full access to the host system.
Impact
Successful exploitation allows an attacker to break out of the vm2 sandbox and execute code with the privileges of the host Node.js process. This leads to full system compromise, including unauthorized access to the host filesystem, environment variables, network resources, and other sensitive host-side data. The impact is critical as it invalidates the security boundary provided by the vm2 library.
Recommendation
- Upgrade to a patched version of
vm2if available or transition to more secure sandboxing solutions, as thevm2project has reached end-of-life. - Update the
DANGEROUS_BUILTINSconfiguration in thevm2library to includetestto block access to thenode:testmodule at the source. - Audit existing configurations to identify and remove
node:testfrom anyrequire.builtinallowlists. - If test capabilities are required, implement a sandbox-local wrapper that does not expose the
run()method,execArgv, or any other host-process control parameters.
Immediate actions
Identify and audit all applications using vm2 in the environment to check for 'node:test' in builtin configurations.
Mitigations
Remove 'node:test' from all vm2 allowlists or move to an alternative sandboxing solution immediately.
CVE-2026-92948