External risk intelligence

vm2 Sandbox Escape Leads to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-92934

vm2 is a sandboxing library used to isolate untrusted JavaScript code execution within a server-side application. While it is a network-accessible component in the context of the application it protects, the library itself is an internal dependency or middleware. Public internet exposure is typically mediated by the host application, not the sandbox component directly.

Remote Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a vulnerability in the vm2 sandboxing library that, if exploited, could allow attackers to escape the sandbox and execute arbitrary code on the system, potentially leading to information disclosure. While the library is designed for security, this specific flaw bypasses its protective measures, posing a significant risk to systems that process untrusted code. The main concern is confirming relevance and exposure.

  • Sandbox escape allows remote code execution.
  • Critical flaw impacts system security and data.
  • Verify if this library is used and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could potentially gain access to a system by exploiting a weakness in how vm2 handles certain errors. If a system uses vm2 to run untrusted code, an attacker might craft malicious input that triggers a specific type of error. When this error is processed, the attacker could then bypass the sandbox's security, leading to the execution of arbitrary code on the server and the potential disclosure of sensitive process information.

  • Requires external network access.
  • Triggered by catching specific host-wrapped errors.
  • Risks remote code execution and information disclosure.

Live Threat

Current exploitation, exposure, and threat context

The vm2 sandboxing library, when certain AggregateError objects are caught within an exception handler, could allow an attacker to bypass cycle detection. This may enable the attacker to access unsanitized proxies embedded in errors, potentially leading to code execution and information disclosure from the sandbox.

  • Sandbox code execution.
  • Bypass cycle detection bypass.
  • Remote code execution and disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 sandboxing library is a common component within applications that execute untrusted JavaScript. In real-world scenarios, ownership of this vulnerability typically falls to the application development or platform engineering teams responsible for the code that embeds and utilizes vm2. The first practical step is to identify all instances of the affected technology, assess their reachability and criticality, and then coordinate remediation with the accountable application owners, potentially involving vendor coordination if vm2 is part of a third-party solution.

  • Application teams should own the remediation.
  • Verify vm2 usage and exposure pathways.
  • Plan coordinated updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library used for?

vm2 is a Node.js library designed to run untrusted JavaScript code in a secure, isolated environment called a sandbox. It is commonly integrated by developers as middleware to prevent guest code from accessing the underlying host system, files, or sensitive processes while performing tasks like evaluating user-provided scripts or plugins.

What does CVE-2026-92934 mean for vm2?

This CVE represents a sandbox escape vulnerability, classified as CWE-693 (Protection Mechanism Failure). It occurs because the library fails to properly sanitize specific error objects. When an application catches a malicious AggregateError, the internal security checks can be bypassed, allowing the code inside the sandbox to break out and execute commands on the host system.

How is this vm2 sandbox escape triggered?

An attacker triggers this by providing input that intentionally generates complex, host-wrapped error objects. When the sandbox exception handler processes these objects, a flaw in cycle detection is exploited to access restricted host proxies. Simply using vm2 or encountering basic errors will not trigger this; it requires specific, malicious input designed to evade the library's error sanitization logic.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal indicates that while the vulnerability is critical, vm2 is an internal dependency. Because public internet exposure is typically mediated by the host application rather than the library itself, the risk depends on whether your application accepts and executes untrusted code from external, network-accessible sources. If the application is internal-only or does not process untrusted input, the likelihood of exploitation is significantly reduced.

What should I do if I use vm2?

First, identify where vm2 is utilized within your applications and verify which versions are currently in use. Coordinate with your development or platform engineering teams to plan an update to a version beyond 3.11.8. Since this is an application-level dependency, remediation involves patching the specific software package and testing the update to ensure it does not disrupt your sandbox functionality.

References