Description
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and the runtime strips only one 'node:' prefix, so a sandbox request for 'node:node:sqlite' resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process's privileges. The issue is fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution Outside the VM Sandbox
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is present in vm2 versions 3.11.3 through 3.11.6 and allows code running in a NodeVM to gain host process privileges. Node.js's host node:sqlite module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable. The module resolver interprets any request beginning with 'node:' as a core‑module request and only strips a single 'node:' prefix. A sandboxed script can therefore request 'node:node:sqlite', causing the resolver to load the node:sqlite entry again. Untrusted code can create a DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library packaged with the untrusted plugin. SQLite loads the library into the Node.js host process and invokes its native entry point, granting the sandboxed code arbitrary native code execution with the host process's privileges.

Affected Systems

The affected product is patriksimek:vm2, specifically all releases from 3.11.3 up to and including 3.11.6. Any Node.js application that incorporates vm2 with builtin modules enabled, particularly node:sqlite, is vulnerable. No other vendors or products are mentioned.

Risk and Exploitability

The CVSS score of 9.4 categorizes this issue as Critical, and while an EPSS score is not available, the exploitation requires only that the offending plugin code be executed within the VM. The vulnerability is not yet listed in the CISA KEV catalog, but the high severity and the ability to load arbitrary native code suggest that exploitation could be straightforward in environments that allow plugin extensions. The likely attack vector is the inclusion of a malicious plugin or a vulnerable third‑party package that enables node:sqlite and database extension loading within the sandbox.

Generated by OpenCVE AI on September 17, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which contains the fix.
  • If an upgrade is not immediately feasible, configure the VM to disallow the node:sqlite module by setting the builtins list to exclude any module that starts with 'node:' or to an empty array, ensuring the vulnerable core module is never exposed.
  • Remove or replace any code that initializes DatabaseSync with extension loading enabled, or otherwise verify that the plugin does not call DatabaseSync.loadExtension().
  • For an additional safeguard, run untrusted VM code in a separate lightweight container or process with limited privileges, so that even if the native extension is loaded, it cannot affect the host process.

Generated by OpenCVE AI on September 17, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6w8r-xxw2-g3hx vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and the runtime strips only one 'node:' prefix, so a sandbox request for 'node:node:sqlite' resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process's privileges. The issue is fixed in vm2 3.11.7.
Title vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:28:41.247Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92938

cve-icon Vulnrichment

Updated: 2026-09-19T02:28:36.823Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:58.750

Modified: 2026-09-19T03:17:18.443

Link: CVE-2026-92938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure