Description
vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Sandbox Escape
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in vm2 between versions 3.9.6 and 3.11.6 permits a built‑in allowlist bypass that enables a sandbox escape. When the embedder explicitly allows the node:test built‑in, the internal lookup treats the scheme‑only key node:test as a generic host passthrough, providing a read‑only proxy to the host module. The proxy forwards calls to node:test.run(), which starts a separate Node process and accepts attacker‑controlled execArgv values, including the ability to supply arbitrary JavaScript via –eval. Executing this JavaScript in the host process yields full control over the system, compromising confidentiality, integrity, and availability.

Affected Systems

This issue affects the vm2 package from patriksimek, specifically versions 3.9.6 through 3.11.6. The exploit requires Node.js version 24 or newer, as those versions expose the node:test scheme‑only key in module.builtinModules.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. While an EPSS score is not available, the lack of a CISA KEV listing does not mitigate the risk, since the vulnerability is already exploitable via a simple require of node:test when enabled in the allowlist. Attackers can launch the exploit from within an application that uses vm2 and has node:test enabled, making exploitation straightforward in such contexts.

Generated by OpenCVE AI on September 17, 2026 at 23:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later to remove the sandbox escape flaw.
  • If upgrading is not immediately possible, remove node:test from the embedder’s allowlist or built‑in whitelist so that the unsafe pathway is inaccessible.
  • After changes, validate that no dangerous built‑in modules, including node:test, are permitted to run within the vm2 sandbox.

Generated by OpenCVE AI on September 17, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qhwx-74w5-xhxq vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/setup-node-sandbox.js strips a single 'node:' prefix before the builtin lookup, sandbox code calling require('node:node:test') resolves to the stored node:test key and receives a readonly proxy to the host module. Calls to node:test.run() are forwarded to the host implementation, which spawns a separate Node process for process-isolated test execution and passes through attacker-controlled execArgv values; supplying --eval=<JavaScript> therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.
Title vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:31:54.395Z

Reserved: 2026-09-17T12:43:03.568Z

Link: CVE-2026-92948

cve-icon Vulnrichment

Updated: 2026-09-18T19:31:25.799Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:00.310

Modified: 2026-09-18T20:17:30.980

Link: CVE-2026-92948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure