Skip to content
Threat Feed
critical advisory

vm2 NodeVM Sandbox Escape via node:test Builtin

The vm2 sandboxing library fails to properly secure the 'node:test' builtin module in Node.js 24+, allowing an attacker to escape the sandbox via a double-prefix require and execute arbitrary host code.

CVE search metadata

CVE search record: CVE-2026-92948. Severity: critical. CVSS: 9.9. EPSS: 0.65%. KEV: no. Product: vm2 (>= 3.9.6, <= 3.11.5). Brief: vm2 NodeVM Sandbox Escape via node:test Builtin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-vm2-node-test-bypass/

The vm2 library (versions 3.9.6 through 3.11.5) contains a critical sandbox escape vulnerability (CVE-2026-92948) when running on Node.js 24 or newer. The issue arises from a failure to correctly restrict the node:test builtin module. When an embedder explicitly allows node:test within a NodeVM configuration, sandboxed code can bypass the intended restrictions by requesting the module using a double prefix, require('node:node:test').

Normalization logic within vm2 resolves this to the node:test module, providing the sandbox with a readonly proxy to the host's test-runner. Because this proxy forwards calls to the host implementation without sufficient API validation, an attacker can invoke node:test.run() and supply arbitrary execArgv flags. By passing flags such as --eval, the attacker can spawn a child process that executes arbitrary JavaScript in an unrestricted host Node.js environment, effectively escaping the vm2 sandbox boundary.

Attack Chain

  1. Attacker identifies a target application utilizing vm2 with node:test explicitly enabled in the require.builtin configuration.
  2. Attacker injects malicious JavaScript into the NodeVM sandbox environment.
  3. Attacker invokes require('node:node:test') within the sandbox to bypass existing builtin restriction filters.
  4. The vm2 sandbox normalizes the path to node:test and grants access to the host's test-runner module.
  5. Attacker executes node:test.run() within the sandbox, supplying a crafted object containing malicious execArgv parameters.
  6. The node:test runner spawns a new Node.js child process using the attacker-supplied execArgv arguments.
  7. The child process executes the attacker's payload (e.g., --eval='require("fs").writeFileSync(...)') outside the sandbox, granting full access to the host system.

Impact

Successful exploitation allows an attacker to break out of the vm2 sandbox and execute code with the privileges of the host Node.js process. This leads to full system compromise, including unauthorized access to the host filesystem, environment variables, network resources, and other sensitive host-side data. The impact is critical as it invalidates the security boundary provided by the vm2 library.

Recommendation

  1. Upgrade to a patched version of vm2 if available or transition to more secure sandboxing solutions, as the vm2 project has reached end-of-life.
  2. Update the DANGEROUS_BUILTINS configuration in the vm2 library to include test to block access to the node:test module at the source.
  3. Audit existing configurations to identify and remove node:test from any require.builtin allowlists.
  4. If test capabilities are required, implement a sandbox-local wrapper that does not expose the run() method, execArgv, or any other host-process control parameters.

Immediate actions

Identify and audit all applications using vm2 in the environment to check for 'node:test' in builtin configurations.

SOC 24h

Mitigations

Remove 'node:test' from all vm2 allowlists or move to an alternative sandboxing solution immediately.

immediate IT Operations

CVE-2026-92948