External risk intelligence

vm2 NodeVM Sandbox Escape Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-92948

This is a vulnerability in a sandboxing library (vm2) used by developers within applications. It requires the developer to explicitly configure the sandbox to allow specific built-in modules (node:test) in a custom implementation. It is not an internet-facing service, appliance, or gateway, and its exposure is limited to the specific, internal code paths defined by the application developer.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability was discovered in the vm2 sandboxing library, impacting Node.js environments. This issue could allow an attacker to bypass security controls within the sandbox, potentially leading to the execution of arbitrary code on the host system. The main concern is to confirm if our internal development practices or applications utilize this specific library in a manner that exposes this risk.

  • Allows code execution outside the sandbox.
  • Potentially impacts secure code execution.
  • Confirm relevance and exposure for development.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by first gaining limited access to a Node.js application that uses the vm2 sandboxing library. If the application is configured to expose the `node:test` module within the sandbox, the attacker can then craft a specific `require` call to bypass the sandbox's protections. This bypass allows the attacker to execute arbitrary JavaScript code on the host system, effectively breaking out of the sandbox and gaining unrestricted control.

  • Requires privileged access to application code.
  • Triggered by calling a specific bypassed module.
  • Arbitrary code execution on the host.

Live Threat

Current exploitation, exposure, and threat context

A sandbox escape vulnerability in vm2 could allow an attacker to execute arbitrary JavaScript code on the host system when specific conditions are met. This occurs when the vm2 sandbox is configured to allow the `node:test` builtin on Node.js 24 or newer, and the attacker can control the `execArgv` values passed to the test execution process.

  • Arbitrary JavaScript execution on host.
  • Requires specific sandbox configuration.
  • Unrestricted host Node.js process.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary responsibility for addressing this vulnerability likely falls on the application development teams who utilize the vm2 library within their Node.js applications, particularly those running on Node.js 24 and newer. The immediate first step is to inventory applications using vm2 and identify those where the `node:test` builtin is explicitly allowed in the sandbox configuration. This will help prioritize remediation efforts based on the business criticality and reachability of the affected applications.

  • Application development teams own this issue.
  • Verify applications using vm2 with `node:test` exposed.
  • Plan vendor coordination and apply updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a Node.js library designed to run untrusted code in a secure, isolated sandbox. Developers use it to execute external or dynamic scripts safely by restricting their access to the host system's resources and sensitive Node.js internals.

How does CVE-2026-92948 allow a sandbox escape?

This vulnerability, classified as CWE-693 (Protection Mechanism Failure), occurs when the sandbox's security boundary is bypassed. By exploiting how the library handles the 'node:test' module on newer Node.js versions, an attacker can trick the system into running code outside the restricted sandbox environment, granting them access to the host's full capabilities.

What must happen for this vulnerability to be triggered?

An attacker needs an environment running Node.js 24 or newer where vm2 is explicitly configured to allow the 'node:test' module. If the sandbox is not configured to include this specific builtin, or if it is running on older Node.js versions, this specific bypass path is not available.

Is this vulnerability likely to be internet-facing?

According to Halo Surface Signal, this is very unlikely to be an internet-facing risk. Because vm2 is a developer library embedded within custom application code, exposure depends entirely on how your specific application is designed and whether it exposes these restricted code paths to external inputs.

What should I do if I am running this software?

Start by identifying all internal applications that utilize the vm2 library. Audit your code to check if 'node:test' is explicitly enabled in the sandbox configuration, particularly on Node.js 24 or newer. If you find this configuration, prioritize updating to vm2 version 3.11.7 or later to resolve the issue.

References