Description
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
Published: 2026-09-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the sandbox escape mechanism of the vm2 NodeVM package, where the DANGEROUS_BUILTINS denylist fails to block the child_process module. This omission allows an attacker to import child_process and execute arbitrary commands on the host. The impact is the ability for an attacker to run any command with the privileges of the process hosting NodeVM, leading to full system compromise. This weakness falls under CWE-184 and CWE-693, indicating improper authorization failure.

Affected Systems

The affected product is VM2 developed by patriksimek, version 3.12.0 and earlier. All versions before 3.12.1 of the vm2 library are impacted. Applications that instantiate NodeVM with configuration options that permit all builtins (builtin: ['*']) or explicitly allow child_process are at risk.

Risk and Exploitability

The CVSS score of 10 indicates that this flaw is of critical severity. The EPSS score is <1% but the missing child_process block suggests that exploitation is feasible where NodeVM is configured insecurely. This vulnerability is not listed in the CISA KEV catalog, but because it allows arbitrary code execution the likelihood of exploitation in environments that use the insecure configuration is high. Attackers can exploit this flaw by instructing NodeVM to load code that requires child_process, effectively escaping the sandbox.

Generated by OpenCVE AI on September 26, 2026 at 06:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade VM2 to version 3.12.1 or later to receive the fix that blocks child_process in the denylist.
  • Configure NodeVM to expose only the builtins required for your application instead of using builtin: ['*'].
  • Explicitly disallow the child_process module in NodeVM configuration until you can audit and confirm that your environment does not rely on it.

Generated by OpenCVE AI on September 26, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pq68-rvw4-xp4r vm2 contains a sandbox escape vulnerability
History

Fri, 25 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-184
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
Title vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
First Time appeared Vm2 Project
Vm2 Project vm2
Weaknesses CWE-693
CPEs cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Vendors & Products Vm2 Project
Vm2 Project vm2
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:51:52.937Z

Reserved: 2026-09-18T11:00:32.756Z

Link: CVE-2026-93605

cve-icon Vulnrichment

Updated: 2026-09-21T17:57:16.750Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:12.340

Modified: 2026-09-21T21:17:19.060

Link: CVE-2026-93605

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-18T13:20:14Z

Links: CVE-2026-93605 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T06:45:06Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-693

    Protection Mechanism Failure