<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Vm2 (&gt;= 3.9.6, &lt;= 3.11.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vm2--3.9.6--3.11.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:20:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vm2--3.9.6--3.11.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>vm2 NodeVM Sandbox Escape via node:test Builtin</title><link>https://feed.craftedsignal.io/briefs/2026-10-vm2-node-test-bypass/</link><pubDate>Thu, 01 Oct 2026 20:20:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vm2-node-test-bypass/</guid><description>The vm2 sandboxing library fails to properly secure the 'node:test' builtin module in Node.js 24+, allowing an attacker to escape the sandbox via a double-prefix require and execute arbitrary host code.</description><content:encoded><![CDATA[<p>The vm2 library (versions 3.9.6 through 3.11.5) contains a critical sandbox escape vulnerability (CVE-2026-92948) when running on Node.js 24 or newer. The issue arises from a failure to correctly restrict the <code>node:test</code> builtin module. When an embedder explicitly allows <code>node:test</code> within a <code>NodeVM</code> configuration, sandboxed code can bypass the intended restrictions by requesting the module using a double prefix, <code>require('node:node:test')</code>.</p>
<p>Normalization logic within <code>vm2</code> resolves this to the <code>node:test</code> module, providing the sandbox with a readonly proxy to the host's test-runner. Because this proxy forwards calls to the host implementation without sufficient API validation, an attacker can invoke <code>node:test.run()</code> and supply arbitrary <code>execArgv</code> flags. By passing flags such as <code>--eval</code>, the attacker can spawn a child process that executes arbitrary JavaScript in an unrestricted host Node.js environment, effectively escaping the vm2 sandbox boundary.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application utilizing <code>vm2</code> with <code>node:test</code> explicitly enabled in the <code>require.builtin</code> configuration.</li>
<li>Attacker injects malicious JavaScript into the <code>NodeVM</code> sandbox environment.</li>
<li>Attacker invokes <code>require('node:node:test')</code> within the sandbox to bypass existing builtin restriction filters.</li>
<li>The <code>vm2</code> sandbox normalizes the path to <code>node:test</code> and grants access to the host's test-runner module.</li>
<li>Attacker executes <code>node:test.run()</code> within the sandbox, supplying a crafted object containing malicious <code>execArgv</code> parameters.</li>
<li>The <code>node:test</code> runner spawns a new Node.js child process using the attacker-supplied <code>execArgv</code> arguments.</li>
<li>The child process executes the attacker's payload (e.g., <code>--eval='require(&quot;fs&quot;).writeFileSync(...)'</code>) outside the sandbox, granting full access to the host system.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to break out of the vm2 sandbox and execute code with the privileges of the host Node.js process. This leads to full system compromise, including unauthorized access to the host filesystem, environment variables, network resources, and other sensitive host-side data. The impact is critical as it invalidates the security boundary provided by the vm2 library.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to a patched version of <code>vm2</code> if available or transition to more secure sandboxing solutions, as the <code>vm2</code> project has reached end-of-life.</li>
<li>Update the <code>DANGEROUS_BUILTINS</code> configuration in the <code>vm2</code> library to include <code>test</code> to block access to the <code>node:test</code> module at the source.</li>
<li>Audit existing configurations to identify and remove <code>node:test</code> from any <code>require.builtin</code> allowlists.</li>
<li>If test capabilities are required, implement a sandbox-local wrapper that does not expose the <code>run()</code> method, <code>execArgv</code>, or any other host-process control parameters.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>sandbox-escape</category><category>nodejs</category><category>code-execution</category></item></channel></rss>