External risk intelligence

vm2 Sandbox Escape via WebAssembly Compromises Node.js Host Capabilities

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92956

The vulnerability exists in a JavaScript sandbox library (vm2) used by developers to execute untrusted code. While common in web applications that process user-provided scripts, the library itself is a dependency rather than an internet-facing service, making public exposure dependent on how it is integrated into a specific application deployment.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the vm2 library, specifically affecting how it handles WebAssembly code within Node.js environments. This issue allows malicious code to escape the intended sandbox, potentially granting unauthorized access to the underlying system. The main concern is confirming if this library is in use and if it is exposed to untrusted code execution.

  • Sandbox escape in JavaScript processing library.
  • Allows unauthorized system access via WebAssembly.
  • Confirm relevance and exposure of the library.

Attack Path

How an attacker could exploit the issue

An attacker can escape the vm2 sandbox by leveraging a flaw in how WebAssembly streaming compilation handles errors. When running on Node.js, the sandbox can be tricked into returning a host-realm error object. By manipulating the Promise behavior, this error can be traced back to the host `Function` constructor, ultimately exposing the real Node.js `process` object and allowing the attacker to execute arbitrary code with host capabilities.

  • No special permissions required to start.
  • Triggered by specific WebAssembly operations.
  • Grants access to host system capabilities.

Live Threat

Current exploitation, exposure, and threat context

The vm2 sandbox, when used with Node.js, could allow an attacker to escape the sandbox environment. This escape is possible when WebAssembly functions are used, enabling malicious code to access host Node.js capabilities, such as file system access, by manipulating Promise behavior to recover the `process` object. This bypasses previous security measures and can occur without requiring specific unsafe configurations.

  • Host Node.js capabilities and modules.
  • Sandbox escape via WebAssembly streaming.
  • Access to host system resources.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library, used for sandboxing JavaScript execution, has a critical sandbox escape vulnerability. Teams responsible for Node.js applications, especially those processing untrusted code, should prioritize identifying deployments of this library. The immediate next step is to confirm the presence and reachability of affected versions, determine business criticality, and assign ownership for remediation planning.

  • Identify application owners and affected code.
  • Verify exposure and impact of vulnerable versions.
  • Plan remediation or implement controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and what is it used for?

vm2 is a JavaScript library designed to create a secure, isolated execution environment for untrusted code within Node.js applications. Developers use it to run third-party scripts or user-provided logic safely by attempting to restrict access to the underlying system. It works as a dependency that acts as a container, preventing the executed code from reaching into the host's memory or accessing sensitive system modules like the file system.

What does sandbox escape mean in the context of CVE-2026-92956?

This vulnerability is a sandbox escape, classified as CWE-693 (Protection Mechanism Failure). It means the security boundary designed to isolate code is broken. In CVE-2026-92956, malicious WebAssembly code can trick the sandbox into revealing a bridge back to the host environment. Once this bridge is established, the code can step outside its restricted container and gain the same permissions as the Node.js process running the application.

How is this sandbox escape triggered?

An attacker triggers this by invoking specific WebAssembly streaming compilation functions. The vulnerability works by forcing the sandbox to return a host-realm error object, which is then manipulated to recover the host's primary process object. It is important to note that this happens automatically; you do not need to have misconfigured the library, enabled specific risky permissions, or used the 'NodeVM' feature for the vulnerability to be active.

Should I be concerned about CVE-2026-92956?

You should prioritize this if your application processes untrusted input using vm2. According to Halo Surface Signal, because vm2 is a code library rather than a standalone internet-facing service, its risk depends entirely on how your application uses it. If your software accepts and runs scripts from external users, the risk is higher. You should audit your dependencies to see if your application relies on a vulnerable version of this library.

How do I fix or mitigate this vulnerability?

The primary resolution is to upgrade to version 3.11.7 or later, which contains the fix. Before applying updates, verify which of your applications currently bundle vm2 versions 3.10.1 through 3.11.6. Once you have identified the affected services, coordinate with the responsible development teams to update the dependency and test that the fix is properly integrated into your deployment pipeline.

References