OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92938

CRITICAL · CVSS 9.9 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions 3.11.3 through 3.11.6 of vm2 expose the Node.js host node:sqlite module to potentially malicious code running in a NodeVM, allowing it to execute arbitrary native code with host privileges. This vulnerability arises from improper sandboxing, enabling attackers to load untrusted native libraries through SQLite's extension loading feature. Organizations utilizing affected versions of vm2 should prioritize immediate updates to version 3.11.7 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92938
Severity
CRITICAL
CVSS
9.9
EPSS
0.62%

Original NVD Description

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and the runtime strips only one 'node:' prefix, so a sandbox request for 'node:node:sqlite' resolves to the configured node:sqlite entry. Sandboxed code can therefore create an in-memory DatabaseSync with extension loading enabled and call DatabaseSync.loadExtension() on a native library bundled in the untrusted plugin package (path derived from __dirname). SQLite loads the library into the Node.js host process and invokes its native entry point, giving the sandboxed plugin arbitrary native code execution outside the sandbox with the host process's privileges. The issue is fixed in vm2 3.11.7.