External risk intelligence

vm2 NodeVM node prefix bypass allows code execution.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-92957

The vulnerability exists in a sandboxing library (vm2) used by developers within application code to isolate untrusted scripts. It is a build-time or library-level dependency rather than a standalone network-facing product, service, or appliance. Public exposure depends entirely on how a developer implements the library in their specific application.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a security vulnerability in the vm2 sandboxing library that could allow untrusted code running within a sandbox to execute arbitrary commands on the host system. While the library has mechanisms to restrict access to built-in modules, a flaw in how it handles certain prefixed module names means these restrictions can be bypassed, potentially leading to unauthorized command execution.

  • Untrusted code can bypass restrictions.
  • A bypass could allow host command execution.
  • Confirm relevance and review usage of the library.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by crafting malicious code that, when executed within a sandboxed environment, bypasses security restrictions related to Node.js built-in modules. This bypass allows the sandboxed code to access and execute host system commands, effectively gaining control over the underlying machine. The vulnerability stems from how the vm2 library handles negative wildcard entries in its require policy, specifically when dealing with `node:`-prefixed module specifiers.

  • Requires unauthenticated access to sandboxed code.
  • Triggers when sandboxed code requires specific Node.js modules.
  • Risk of host command execution.

Live Threat

Current exploitation, exposure, and threat context

Untrusted code within a sandboxed environment could execute arbitrary host commands by bypassing security policies intended to restrict access to Node.js built-in modules. This could occur when the sandboxing library incorrectly handles specially crafted module requests, allowing access to sensitive APIs.

  • Arbitrary host command execution.
  • Bypassing security policy restrictions.
  • Complete host system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts applications using the vm2 library for sandboxing, potentially allowing code within the sandbox to execute host commands. Application owners and platform teams are likely responsible for managing this risk, as it involves a developer dependency. The first practical step is to identify all instances of the affected vm2 version, assess their exposure and criticality, and coordinate remediation with development teams and potentially the vendor.

  • Application owners must prioritize remediation.
  • Verify vm2 usage and version in sandboxed environments.
  • Plan maintenance or vendor coordination for updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a Node.js library designed to create isolated execution environments, known as sandboxes. Developers use it to safely run untrusted code by restricting the APIs available to that code. It acts as a safety barrier within an application, preventing external scripts from interacting with the underlying host system's file storage, network, or process controls.

What does CVE-2026-92957 mean for sandbox security?

This vulnerability, classified as CWE-269, involves an improper privilege management flaw. When developers define policies to block specific Node.js modules, vm2 fails to recognize those same modules if they include a 'node:' prefix. An attacker can use this inconsistency to bypass security restrictions, gaining access to restricted host-level features like process spawning.

How can an attacker trigger this vulnerability?

The trigger requires the ability to supply or influence code that runs within a vm2 sandbox. If the application's configuration attempts to block a module using a wildcard—such as '-node:child_process'—the bypass occurs when the sandboxed code requests the module without the prefix or by using the canonical name. Code that does not use the 'require' function to access restricted modules is not affected.

Is my application vulnerable if it uses vm2?

According to Halo Surface Signal, this risk depends on your specific application implementation. Because vm2 is a code dependency rather than a standalone network appliance, you are primarily at risk if your application processes untrusted user input within a sandbox. You should determine if your application's sandbox configuration uses 'require' policies to restrict access to sensitive built-in modules.

How should I address this issue in my software?

The primary response is to update your project's dependencies. The vm2 library was patched in version 3.11.7 to correctly normalize and restrict 'node:'-prefixed modules. You should audit your codebase to identify where vm2 is implemented, confirm the version in use, and coordinate with your development team to upgrade to the secure version or later.

References