OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92956

CRITICAL · CVSS 10 EPSS 0.59% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions 3.10.1 through 3.11.6 of vm2 are vulnerable to a critical sandbox escape that allows attackers to gain unauthorized access to the host Node.js environment, including sensitive modules like the filesystem. This vulnerability can be exploited without requiring unsafe configurations, making it particularly dangerous for applications utilizing vm2 in a default setup. Organizations using affected versions should prioritize upgrading to 3.11.7 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92956
Severity
CRITICAL
CVSS
10
EPSS
0.59%

Original NVD Description

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real host `process` object, gaining host Node.js capabilities (e.g. access to host modules such as fs) in the context of the process running the sandbox. No NodeVM, require permission, host object injection, or otherwise unsafe configuration is required. This is a bypass of the fix for GHSA-6j2x-vhqr-qr7q, which removed the JSPI entry points WebAssembly.promising and WebAssembly.Suspending. The issue is fixed in 3.11.7.