OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92935

CRITICAL · CVSS 9 EPSS 0.67% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the vm2 sandbox for Node.js, specifically in versions 3.11.4 to 3.11.6, allowing attackers to bypass security restrictions and execute arbitrary commands within the host Node.js process. By exploiting a flaw in the NodeVM constructor's handling of the `require` option, an attacker can create an inner NodeVM with custom privileges, effectively escaping the sandbox environment. Organizations using affected versions of vm2 should prioritize upgrading to version 3.11.7 to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92935
Severity
CRITICAL
CVSS
9
EPSS
0.67%
Java

Original NVD Description

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array into undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. As a result, an attacker who can supply JavaScript executed by a NodeVM configured with truthy `nesting` and an array-shaped `require` (e.g. `new NodeVM({nesting: true, require: []})`) can require the host `vm2` module, create an inner NodeVM with an attacker-chosen builtin allowlist (such as `child_process`), and execute arbitrary commands with the privileges of the host Node.js process, escaping the sandbox. Outer builtin restrictions do not constrain the attacker-created inner NodeVM. This issue is fixed in vm2 3.11.7.