Description
vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpaths such as fs/promises. Sandboxed code can therefore call require('fs/promises') or require('node:fs/promises') and reach the promise-based filesystem API despite fs being denied; node: prefix handling is likewise inconsistent (a -node:fs/promises entry does not block require('fs/promises')). Host file creation and writing were confirmed via fsp.writeFile(), and other fs/promises operations (cp, mkdir, rename, rm, rmdir, truncate, read operations, etc.) are also reachable. This issue is fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Denylist Bypass
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows sandboxed code to import 'fs/promises' even when the standard builtin denylist is intended to block access to the 'fs' module. This bypass results in the exposed promise‑based filesystem API, permitting file creation, deletion, and other filesystem operations within the VM. The consequence is that a sandboxed script can read or modify host files, potentially leading to data compromise or further code execution.

Affected Systems

The issue affects the vm2 library maintained by patriksimek. All versions through 3.11.6 are impacted; the vulnerability is mitigated in release 3.11.7 onwards. Any application that embeds vm2 and configures the built‑in denylist (e.g., require: { builtin: ['*', '-fs', '-child_process']}) is at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. EPSS is currently not available, but the lack of a KEV listing does not diminish the potential exploitation path: an attacker controlling sandboxed code can once the bypass is in place perform privileged file operations. The actual attack vector requires that the host application uses the built‑in denylist and allows the sandbox to import modules. Given the fixed nature in newer releases, this represents a well‑understood, but currently exploitable flaw.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or newer to remove the denylist bypass.
  • Review the vm2 configuration for require.builtin usage; replace the wildcard '*' with a specific allowlist and remove negative patterns for fs, or switch to an allowlist approach to explicitly permit only necessary modules.
  • Employ operating‑system level isolation (e.g., containers, namespaces, chroot) to limit file system visibility for sandboxed code, ensuring that even if fs/promises is accidentally exposed, it operates within a restricted directory tree.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6rh5-qq4q-97xh vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpaths such as fs/promises. Sandboxed code can therefore call require('fs/promises') or require('node:fs/promises') and reach the promise-based filesystem API despite fs being denied; node: prefix handling is likewise inconsistent (a -node:fs/promises entry does not block require('fs/promises')). Host file creation and writing were confirmed via fsp.writeFile(), and other fs/promises operations (cp, mkdir, rename, rm, rmdir, truncate, read operations, etc.) are also reachable. This issue is fixed in vm2 3.11.7.
Title vm2 before 3.11.7 Denylist Bypass via fs/promises
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:35:47.679Z

Reserved: 2026-09-17T12:43:31.527Z

Link: CVE-2026-92958

cve-icon Vulnrichment

Updated: 2026-09-18T19:35:22.343Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:01.970

Modified: 2026-09-18T20:17:31.243

Link: CVE-2026-92958

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T13:46:15Z

Links: CVE-2026-92958 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control

  • CWE-269

    Improper Privilege Management