Description
vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Host Command Execution
Action: Immediate Patch
AI Analysis

Impact

The bug in vm2 up to version 3.11.6 allows a sandboxed program to bypass a deny list when loading built‑in modules. Because NodeVM removes the 'node:' prefix during runtime resolution but compares deny entries against the canonical names, a policy such as '-node:child_process' fails to block access to the real 'child_process' builtin. The attacker can then import this module and invoke process‑spawning functions such as execSync or spawn, giving host command‑execution capabilities. This is an access‑control failure identified as CWE‑269.

Affected Systems

All installations of the patriksimek vm2 package with a working directory that includes a NodeVM configuration that attempts to deny 'node:child_process' on builtin modules. The vulnerability exists in all releases through 3.11.6 and is resolved in version 3.11.7 and later.

Risk and Exploitability

The CVSS score of 9.4 marks the flaw as critical. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: any untrusted code executed within a NodeVM can exploit the bypass to load the child_process builtin, spawn system processes, and potentially escape the sandbox. Because the bug occurs at runtime, no special conditions beyond possessing a NodeVM configuration with a deny list are required.

Generated by OpenCVE AI on September 26, 2026 at 16:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or newer, where the deny‑list comparison bug is fixed.
  • Reconfigure NodeVM require policies to use only canonical builtin names or to rely on an allow list, avoiding 'node:' prefixes entirely.
  • Where upgrading is infeasible, remove deny entries that contain 'node:' prefixes or disable the use of NodeVM for untrusted code, and run such code in a separately isolated container or environment.

Generated by OpenCVE AI on September 26, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8686-vhfx-7r3j vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
History

Sat, 26 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7. (Suggested title: "vm2 before 3.11.7: NodeVM builtin deny-list bypass via node:-prefixed specifiers exposes child_process") vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.
Title vm2 before 3.11.7 Authentication Bypass via node: Prefix vm2 before 3.11.7 NodeVM Builtin Deny-List Bypass via node: Prefix

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7. (Suggested title: "vm2 before 3.11.7: NodeVM builtin deny-list bypass via node:-prefixed specifiers exposes child_process")
Title vm2 before 3.11.7 Authentication Bypass via node: Prefix
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T13:30:01.519Z

Reserved: 2026-09-17T12:43:31.527Z

Link: CVE-2026-92957

cve-icon Vulnrichment

Updated: 2026-09-17T17:25:15.575Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:01.813

Modified: 2026-09-26T14:17:00.297

Link: CVE-2026-92957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T16:45:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management