Description
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
Published: 2026-09-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution in host Node.js process
Action: Immediate Patch
AI Analysis

Impact

vm2 versions prior to 3.11.7 contain a sandbox escape flaw that allows an attacker who can execute the vm2 CLI to run arbitrary code in the host Node.js process. The vulnerability is triggered by supplying a malicious script file that calls require(__filename), causing the script to re‑execute itself outside the sandbox and access host modules such as fs and child_process. The effect is full control over the host process, enabling file manipulation, arbitrary commands, and potentially complete system compromise. This vulnerability is identified as CWE‑453. The description makes clear that the impact is code execution, with the potential to read, modify, and execute files on the machine running the process.

Affected Systems

The affected product is vm2, a sandboxing framework delivered by patriksimek. Versions earlier than 3.11.7 are impacted. Any deployment of vm2 that relies on the CLI interface and may receive malicious script input is vulnerable.

Risk and Exploitability

The CVSS base score of 9.3 indicates critical severity. Because the flaw requires the attacker to run the vm2 CLI, the vector is inferred to be local or command‑line execution; remote exploitation would necessitate another vulnerability to gain CLI access. The EPSS score is not available, but the absence of a record in the CISA KEV catalog suggests no widespread public exploitation has been reported yet. Nonetheless, the high severity and the ability to escape the sandbox make this a risk worth addressing promptly.

Generated by OpenCVE AI on September 17, 2026 at 21:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later where the sandbox escape issue has been fixed.
  • If an upgrade is not immediately possible, remove or restrict the vm2 CLI from the environment, ensuring that no untrusted script can be executed via the CLI interface.
  • Consider isolating the vm2 execution within a dedicated user context or container, limiting file system and process‑management privileges for the sandboxed environment.

Generated by OpenCVE AI on September 17, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jxxv-8r27-vm4p vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
History

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
Title vm2 before 3.11.7 Sandbox Escape via CLI require
Weaknesses CWE-453
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:24:26.002Z

Reserved: 2026-09-17T12:43:03.568Z

Link: CVE-2026-92950

cve-icon Vulnrichment

Updated: 2026-09-17T14:24:20.651Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:00.637

Modified: 2026-09-17T15:17:00.910

Link: CVE-2026-92950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-453

    Insecure Default Variable Initialization