External risk intelligence

vm2 Sandbox Escape via Improper `require` Handling

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-92935

vm2 is a library-level sandbox component integrated by developers into Node.js applications to execute untrusted code. It is not a standalone network-facing product, service, or appliance. Exposure depends entirely on how a developer chooses to implement the sandbox within their own application logic, making public internet exposure of this specific component unlikely in typical deployments.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in vm2, a Node.js code sandbox, that could allow an attacker to bypass security controls and execute arbitrary commands with the privileges of the host process. The issue arises from how the sandbox handles specific configurations, potentially enabling an escape from the intended sandboxed environment.

  • Sandbox could be escaped by attackers.
  • Leadership should remember the risk of sandboxes being bypassed.
  • Confirm if this sandbox technology is in use.

Attack Path

How an attacker could exploit the issue

An attacker could escape a Node.js sandbox by providing specially crafted input to a sandboxed environment. This involves tricking the sandbox into misinterpreting a `require` option, allowing the attacker to create a new, less restricted sandbox within the original one. This inner sandbox can then be used to execute arbitrary commands on the host system.

  • Requires attacker-controlled code execution.
  • Triggers when `require` is an array.
  • Leads to arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to execute arbitrary commands with the privileges of the host Node.js process, effectively escaping the sandbox. This occurs when a NodeVM is configured with specific nesting and require options, enabling the attacker to create an inner NodeVM with an allowlist that includes the `child_process` module.

  • Host Node.js process commands at risk.
  • Attacker-controlled inner VM escapes sandbox.
  • Arbitrary command execution by the attacker.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in vm2 impacts applications that use the NodeVM constructor for sandboxing untrusted Node.js code. Typically, application owners or the platform teams responsible for the Node.js runtime environment would lead the remediation efforts. The initial practical step involves identifying all instances of vm2 within the organization's codebase and infrastructure, assessing their reachability and criticality, and then coordinating the update with the vendor or applying the fix during a planned maintenance window.

  • Application owners should manage the fix.
  • Verify if vm2 is in use.
  • Plan coordinated updates or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 software library?

vm2 is a JavaScript library used by developers to build sandboxed environments within Node.js applications. It allows programs to safely run untrusted code by isolating it from the host system's main resources and sensitive files, acting as a protective barrier when executing external scripts.

How does CVE-2026-92935 affect the sandbox?

This vulnerability is classified as CWE-913, which involves the improper control of dynamically managed code resources. In vm2, the sandbox fails to correctly validate the `require` configuration. This flaw allows an attacker to bypass security restrictions, effectively escaping the isolation layer to run arbitrary commands on the underlying host.

What conditions trigger this sandbox escape?

The escape occurs when a developer configures the NodeVM instance with `nesting: true` and provides an array-shaped `require` option. Simply using vm2 does not trigger the bug; the vulnerability is only activated if an attacker can supply code to be executed within a NodeVM environment specifically misconfigured in this manner.

Is my application at risk via internet exposure?

Halo Surface Signal indicates that vm2 is a library-level component rather than a standalone network appliance. Because it is embedded directly into application code, its exposure is not determined by network-facing status alone, but rather by whether an attacker can supply untrusted code to your specific, vulnerable implementation.

What should I do to fix this vm2 vulnerability?

Your first step is to identify where vm2 is used within your codebase. Once located, confirm if your NodeVM configurations use the affected options. You should then coordinate with your development team to update the vm2 library to version 3.11.7 or later, which contains the necessary security patch.

References