External risk intelligence

vm2 NodeVM Sandbox Escape via Child Process Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-93605

vm2 is a library used within Node.js applications to sandbox code execution. While it can be integrated into internet-facing applications that process user-provided code, it is a developer library rather than a standalone network service or appliance, making its exposure entirely dependent on the specific implementation of the host application.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the vm2 NodeVM library that could allow unauthorized command execution on host systems. This occurs when the library's sandbox escape mechanism fails to properly restrict access to critical system functions, potentially exposing systems to risk if configured in a specific way. The primary concern is to confirm if and how this technology is implemented within our environment.

  • Code sandbox bypass allows command execution.
  • Critical for applications that run untrusted code.
  • Confirm relevance and exposure within our systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted code to a Node.js application that uses the vm2 library. If the application is configured to allow certain built-in Node.js modules within the sandbox, the attacker's code could break out of the sandbox and execute commands on the underlying server. This could allow an attacker to gain control of the host system.

  • Network exposure, no special access needed.
  • Malicious code sent to the application.
  • Arbitrary command execution on the host.

Live Threat

Current exploitation, exposure, and threat context

When configured with explicit allowances for `child_process`, this vulnerability could permit arbitrary command execution on the host system by bypassing the intended sandbox environment. This scenario could arise if an application utilizes vm2 to execute untrusted code and permits the `child_process` module, potentially affecting system integrity and allowing unauthorized operations.

  • Host system commands could be executed.
  • Untrusted code execution could trigger the bypass.
  • Unauthorized system operations may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vm2 library's sandbox escape vulnerability likely impacts application owners and platform teams responsible for Node.js environments. The immediate priority is to identify all instances of the affected technology, confirm their reachability and criticality, and then assign an accountable owner for remediation planning.

  • Application owners and platform teams should investigate.
  • Verify vm2 usage and configuration in Node.js applications.
  • Plan remediation based on identified risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a Node.js library designed to run untrusted code in a secure, isolated environment called a sandbox. Developers use it to safely execute user-provided scripts within their applications, preventing that code from accessing the underlying host system or sensitive files. It acts as a safety barrier between external inputs and the server's local operating environment.

Why does CVE-2026-93605 lead to a sandbox escape?

This vulnerability is a Protection Mechanism Failure, specifically CWE-693. While vm2 is intended to block dangerous system functions, it fails to include 'child_process' in its denylist of restricted modules. Because this module allows for the execution of system commands, an attacker can use it to break out of the intended sandbox and run unauthorized code directly on the host system.

How can an attacker trigger this vulnerability?

An attacker triggers this by providing malicious code to an application that uses a vulnerable version of vm2. The bypass succeeds specifically when the developer has configured the sandbox to allow built-in modules, such as by using the builtin:['*'] setting or explicitly permitting child_process. If the sandbox is configured to strictly forbid these modules, the vulnerability cannot be used in this way.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal notes that since vm2 is a developer library rather than a standalone network appliance, risk depends entirely on your specific implementation. While it is classified as external, you are only at risk if your application is internet-facing and uses this library to process untrusted code from users in a permissive configuration.

How should I respond if I use vm2 in my code?

First, conduct an audit to identify where vm2 is implemented and verify your current configuration settings regarding module allowances. Once you have mapped these instances, prioritize updating the library to version 3.12.1 or later. Ensure your team documents these usage points to confirm that remediation steps are applied to every instance of the technology.

References