{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vm2--3.12.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-92935"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (\u003e= 3.11.4 and \u003c= 3.11.6)","vm2 (3.11.6)","vm2 (3.11.3-3.11.6)","vm2 (3.11.3 - 3.11.6)","vm2 (3.10.2 - 3.11.6)","vm2 (\u003c 3.11.7)","vm2 (\u003e= 3.9.6, \u003c= 3.11.6)","vm2 (3.11.0-3.11.7)","vm2 (3.10.1 - 3.11.6)","vm2 (\u003c= 3.11.6)","vm2 (\u003c= 3.12.0)"],"_cs_severities":["critical"],"_cs_tags":["sandbox-escape","nodejs","code-execution","vulnerability","vm2","rce","javascript","cve","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe vm2 library, commonly used as a sandbox for executing untrusted Node.js code, contains a critical vulnerability (CVE-2026-92935) in its NodeVM constructor logic. In versions 3.11.4 through 3.11.6, the \u003ccode\u003ehasRealRequireConfig\u003c/code\u003e check fails to correctly validate the \u003ccode\u003erequire\u003c/code\u003e option when provided as an array. Specifically, passing an array-shaped \u003ccode\u003erequire\u003c/code\u003e object satisfies the guard meant to reject nesting without explicit configuration.\u003c/p\u003e\n\u003cp\u003eThis logic flaw allows an attacker to manipulate the \u003ccode\u003emakeResolverFromLegacyOptions()\u003c/code\u003e function, leading to the creation of a resolver that exposes the host's \u003ccode\u003evm2\u003c/code\u003e module. By supplying a payload that initiates a \u003ccode\u003eNodeVM\u003c/code\u003e with \u003ccode\u003enesting: true\u003c/code\u003e and a malicious \u003ccode\u003erequire\u003c/code\u003e array, an attacker can escape the sandbox boundaries. Once escaped, the attacker can create an inner \u003ccode\u003eNodeVM\u003c/code\u003e with arbitrary builtin privileges, such as \u003ccode\u003echild_process\u003c/code\u003e, enabling the execution of arbitrary commands under the context of the host Node.js process. This vulnerability is addressed in vm2 version 3.11.7.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full sandbox escape and arbitrary code execution within the host environment. This impacts any application relying on vm2 for isolation of untrusted JavaScript, potentially leading to unauthorized data access, system-level command execution, and full compromise of the Node.js application process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the vm2 dependency to version 3.11.7 or later across all applications utilizing this library to mitigate CVE-2026-92935.\u003c/li\u003e\n\u003cli\u003eAudit all application code utilizing the \u003ccode\u003eNodeVM\u003c/code\u003e constructor to ensure the \u003ccode\u003erequire\u003c/code\u003e configuration is strictly defined as an object rather than an array.\u003c/li\u003e\n\u003cli\u003eImplement process-level sandboxing (e.g., containers, gVisor) as a secondary defense layer to limit the impact of a potential sandbox escape.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:06:32Z","date_published":"2026-09-17T15:57:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/","summary":"An improper validation of the 'require' configuration in the vm2 Node.js sandbox allows attackers to bypass nesting restrictions and achieve arbitrary code execution by spawning an inner NodeVM with elevated privileges.","title":"Sandbox Escape in vm2 via NodeVM Configuration Misvalidation","url":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Vm2 (\u003c= 3.12.0)","version":"https://jsonfeed.org/version/1.1"}