External risk intelligence

vm2 Sandbox Escape via NodeVM console

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92955

vm2 is a server-side JavaScript library used by developers to create isolated execution environments. It is a dependency integrated into applications rather than a standalone network-facing service, edge gateway, or appliance. Exposure is dependent on the specific implementation of the host application, making direct public-internet accessibility of the library itself very unlikely.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in vm2, a Node.js library used for creating secure, isolated JavaScript environments. The vulnerability allows malicious code to escape the sandbox and execute commands with broad system access, bypassing security restrictions. The primary concern is to confirm if this library is in use and if it is exposed to potential exploitation.

  • Code can break out of secure environments.
  • Confirms if this library is being used.
  • Understand potential impact and verify use.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a sandbox escape vulnerability within the NodeVM feature of vm2. This occurs when an attacker manipulates the `__proto__` getter/setter via `console._stdout` or `console._stderr`, allowing them to overwrite `EventEmitter.prototype.emit`. By triggering process events, the attacker can bypass code generation restrictions and execute arbitrary code with the privileges of the running process.

  • No authentication or special access is required.
  • Triggered by manipulating console output.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A sandbox escape vulnerability in vm2 could allow attackers to execute code with process-level permissions, potentially impacting the host system when the library is used to execute untrusted code.

  • Code execution with process context.
  • Bypassing sandbox restrictions on untrusted code.
  • Compromise of the host system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library, a Node.js sandbox environment, has a critical vulnerability allowing for sandbox escapes. In a real-world scenario, the application development team or platform team responsible for integrating vm2 into their services would likely own this issue. The first practical step is to identify all applications that utilize vm2, confirm their business criticality and exposure, and then plan remediation based on the identified risk.

  • Application development teams should own the issue.
  • Verify vm2 usage and deployment scope.
  • Plan remediation based on risk and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is vm2 and why is it used?

vm2 is a Node.js library designed to run untrusted JavaScript code within a secure, isolated sandbox environment. Developers integrate it into their applications to safely execute code provided by users or external sources, preventing that code from directly accessing the underlying system's sensitive resources.

What is the vulnerability in CVE-2026-92955?

This vulnerability is a sandbox escape, classified as CWE-913 (Improper Control of Dynamically-Managed Code Resources). It allows code running inside the NodeVM to interact with protected host properties like the __proto__ getter. By manipulating console outputs, an attacker can overwrite core event emitters, effectively breaking out of the isolation to execute arbitrary code with the same privileges as the main application.

How can an attacker trigger this sandbox escape?

An attacker triggers this by interacting with the NodeVM's console objects, specifically _stdout or _stderr, to manipulate the environment's prototype chain. The bug is not triggered by standard, safe execution of trusted code; it specifically requires the ability to provide malicious, crafted input that the sandbox environment then processes.

Is my application at risk if it uses vm2?

Halo Surface Signal indicates that vm2 is a code dependency rather than a standalone network service, so it is not directly reachable from the internet. Your risk depends on whether your application accepts and executes untrusted input within a NodeVM instance. If your service acts as a bridge for user-supplied scripts, it requires higher priority for review.

How do I respond to this advisory?

Your first step is to perform an inventory of your software stack to identify if and where vm2 is used. Once identified, coordinate with your development teams to determine if the library is processing untrusted input. If it is, prioritize updating to a version beyond 3.11.8 to resolve the sandbox escape risk.

References