Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-92951: CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2

CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2 Vulnerability ID: CVE-2026-92951 CVSS Score: 9.9 Published: 2026-10-01 An incorrect authorization and directory traversal vulnerability in the vm2 library before version 3.11.7 allows remote attackers to bypass the sandbox's external package allowlist. This flaw permits sandboxed code to resolve and execute arbitrary…

CVE-2026-92951 represents a significant vulnerability in the vm2 library, enabling remote attackers to bypass the sandbox and execute arbitrary host code with full privileges. This flaw was discovered in versions of vm2 prior to 3.11.7 and is rated with a critical CVSS score of 9.9. The vulnerability exists due to incorrect authorization and directory traversal weaknesses within the library's external package allowlist mechanism.

Specifically, vm2 uses unanchored substring matching in its bare-specifier matcher, which fails to properly filter out directory traversal sequences. This allows malicious code to resolve and execute arbitrary host packages, leading to a full sandbox escape and unauthorized host code execution.

The exploit status for this vulnerability is currently a Proof of Concept (PoC), meaning a working exploit has been demonstrated but is not actively used in the wild. The vulnerability is classified under CWE-706 (Incorrect Authorization), CWE-863 (Missing Authorization), and CWE-829 (Invalid Data) according to the Common Weakness Enumeration (CWE). The attack vector is identified as Network, indicating that the exploit can be executed remotely over a network connection.

Affected systems include any application that relies on vm2 to execute untrusted code, particularly those using NodeVM configurations, multi-tenant plugin hosting systems with vm2 external module allowlists, serverless runtimes, and webhooks utilizing deprecated vm2 sandbox instances. Users of these systems are strongly advised to upgrade to vm2 version 3.11.7 or later, which fixes the external-package allowlist bypass.

To mitigate the risk of exploitation, developers are encouraged to implement strong OS-level sandboxing measures, such as AppArmor, gVisor, or Docker with non-root configurations. Additionally, ensuring that direct and transitive dependencies on the vm2 package are updated to the patched version is crucial. This can be achieved by updating the dependency in the project's lockfile from vm2 to ^3.11.7 and then running the package manager's installation command to apply the patch.

Developers should also verify that the compiled regex mappings inside lib/resolver-compat.js now match the correctly anchored patterns to prevent directory traversal sequences.

Further details, including functional unit tests that demonstrate the bypasses, can be found in the GitHub security advisory, which provides comprehensive proof of concept test cases. The National Vulnerability Database (NVD) and the Common Vulnerabilities and Exposures (CVE) database have also catalogued this vulnerability for reference and tracking purposes.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Understanding Prototypes in JavaScript: A Practical Guide for Developers

JavaScript uses prototypes to support inheritance, property lookup, and shared behavior between objects. Although modern syntax gives us classes and familiar object-oriented patterns, prototypes…

  • JavaScript uses prototypes for inheritance and shared behavior among objects
  • Every object has an internal prototype reference for property lookup
  • Prototype chain enables shared methods across instances and constructor functions

Structured Logging and Distributed Tracing: Moving Beyond console.log

We have all been there during an outage: staring at terminal logs searching for an error: [2026-09-25 02:14:12] Error processing request: object is None [2026-09-25 02:14:12] Failed to charge credit…

  • Structured JSON logging provides machine-readable, queryable format for complex systems
  • Correlation IDs enable tracing request lifecycle across multiple services
  • Middleware implementation facilitates attaching correlation ID to requests in frameworks

"A second operation was started on this context" — the EF Core bug that only shows up under load

"A Second Operation Was Started on This Context" — The EF Core Bug That Only Shows Up Under Load You’ve debugged this error before: InvalidOperationException: A second operation was started on this…

  • Second operation started on EF Core bug under load conditions.
  • Root cause: service-lifetime design issue with fire-and-forget context leak.
  • Resolution: ensure one scope per unit of work, manage scopes explicitly.

Trying unknown Mac software without trusting it: a disposable macOS VM on Apple Silicon

At some point you want to try a Mac app you don't fully trust: a menu bar utility from a one-person shop, an installer someone linked in a forum, a CLI that wants sudo .

  • Disposable macOS VM on Apple Silicon tests unknown software safely.
  • VM provides separate macOS environment without affecting host system.
  • Requirements include Apple Silicon Mac, macOS 14, and compatible VM application.

An uncalibrated classifier is worse than no classifier

What I learned building a website that rewrites itself for whoever is reading it, on ₹0 of infrastructure. Project Blog : https://santhosh-reddy.vercel.app/en/blog/8 Project Breakdown…

  • Uncalibrated classifier performs worse than no classifier
  • Poorly calibrated traffic split leads to slower convergence
  • Calibration solution over raw accuracy improvement

More from Friday 2 October →