External risk intelligence

vm2 Node.js SQLite Module Allows Native Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-92938

This vulnerability affects a sandboxing library (vm2) used within Node.js applications. While it is often used in back-end environments, its exposure depends entirely on whether the application utilizing the library processes untrusted input from the internet. It is not an inherently public-facing service itself, but its reachability depends on the specific architecture of the hosting application.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the vm2 sandboxing library, impacting Node.js applications. This issue allows code running within the sandbox to execute arbitrary native code on the host system with elevated privileges, bypassing security controls. The main concern is confirming relevance and exposure within our environments.

  • Unsafe code execution in Node.js sandboxes.
  • Could allow attackers to gain host system control.
  • Confirm if our applications use this library.

Attack Path

How an attacker could exploit the issue

An attacker with low-privilege access to an application using a vulnerable version of vm2 could craft a malicious plugin. This plugin, when loaded by the application, leverages the exposed Node.js `node:sqlite` module to enable extension loading. By calling `DatabaseSync.loadExtension()` with a path to a specially designed native library within the plugin, the attacker can execute arbitrary native code on the host system with the application's privileges.

  • Low-privilege access required.
  • Vulnerable vm2 loads untrusted native code.
  • Risk of arbitrary host code execution.

Live Threat

Current exploitation, exposure, and threat context

When the `node:sqlite` module is permitted within a sandboxed Node.js environment, malicious code could exploit this by enabling extension loading and executing arbitrary native code within the host process. This occurs when a request for 'node:node:sqlite' is processed, allowing a specially crafted plugin to load a native library.

  • Host process native code execution.
  • Sandboxed code loads untrusted native library.
  • Arbitrary code execution in host process.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library's vulnerability requires attention from teams managing Node.js applications that utilize sandboxing, potentially including platform, application, and security engineering teams. The initial step involves inventorying all instances of vm2, confirming their reachability, and assessing their criticality to business operations to prioritize remediation efforts with the accountable owners.

  • Own: Platform and application engineering teams.
  • Verify: Identify all vm2 deployments and exposure.
  • Act: Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library used for in Node.js?

vm2 is a sandboxing library designed to execute untrusted JavaScript code in an isolated environment. Developers use it to safely run external plugins or user-provided scripts within Node.js applications, aiming to restrict that code from accessing sensitive parts of the host system or internal system functions.

How does CVE-2026-92938 allow code execution?

This vulnerability is a Protection Mechanism Failure (CWE-693). It allows sandboxed code to escape its isolation by incorrectly accessing the host's 'node:sqlite' module. By manipulating how modules are resolved, malicious code can load external native libraries directly into the host process, granting the code full control over the system with the application's native privileges.

Does any use of vm2 trigger this vulnerability?

No. The vulnerability is only reachable when the sandbox configuration explicitly permits access to the 'node:sqlite' module, either by name or by allowing all built-in modules. If the application environment does not expose this specific module to the sandboxed code, this particular attack path is effectively blocked.

How do I know if my application is at risk?

According to Halo Surface Signal, risk depends on your application's architecture. While vm2 is not a public-facing service itself, your application is at risk if it uses a vulnerable version of vm2 and processes untrusted input from the internet within a sandbox that has the SQLite module enabled.

What is the first step to address this CVE?

Start by auditing your codebase to identify all instances where the vm2 library is used. Determine if your sandbox configurations permit the 'node:sqlite' module. If you are using version 3.11.3 through 3.11.6, prioritize updating to version 3.11.7 or later to fully resolve the underlying module resolution flaw.

References