{
  "id": 11337273,
  "title": "CVE-2026-92951: CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2",
  "url": "https://urgent.news/2026/10/02/cve-2026-92951-cve-2026-92951-sandbox-escape-via-external-package",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T02:31:02.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/cverports/cve-2026-92951-cve-2026-92951-sandbox-escape-via-external-package-allowlist-bypass-in-vm2-1l33"
  },
  "original_language": "en",
  "account": "CVE-2026-92951 represents a significant vulnerability in the vm2 library, enabling remote attackers to bypass the sandbox and execute arbitrary host code with full privileges. This flaw was discovered in versions of vm2 prior to 3.11.7 and is rated with a critical CVSS score of 9.9. The vulnerability exists due to incorrect authorization and directory traversal weaknesses within the library's external package allowlist mechanism. Specifically, vm2 uses unanchored substring matching in its bare-specifier matcher, which fails to properly filter out directory traversal sequences. This allows malicious code to resolve and execute arbitrary host packages, leading to a full sandbox escape and unauthorized host code execution.\n\nThe exploit status for this vulnerability is currently a Proof of Concept (PoC), meaning a working exploit has been demonstrated but is not actively used in the wild. The vulnerability is classified under CWE-706 (Incorrect Authorization), CWE-863 (Missing Authorization), and CWE-829 (Invalid Data) according to the Common Weakness Enumeration (CWE). The attack vector is identified as Network, indicating that the exploit can be executed remotely over a network connection.\n\nAffected systems include any application that relies on vm2 to execute untrusted code, particularly those using NodeVM configurations, multi-tenant plugin hosting systems with vm2 external module allowlists, serverless runtimes, and webhooks utilizing deprecated vm2 sandbox instances. Users of these systems are strongly advised to upgrade to vm2 version 3.11.7 or later, which fixes the external-package allowlist bypass.\n\nTo mitigate the risk of exploitation, developers are encouraged to implement strong OS-level sandboxing measures, such as AppArmor, gVisor, or Docker with non-root configurations. Additionally, ensuring that direct and transitive dependencies on the vm2 package are updated to the patched version is crucial. This can be achieved by updating the dependency in the project's lockfile from vm2 to ^3.11.7 and then running the package manager's installation command to apply the patch. Developers should also verify that the compiled regex mappings inside lib/resolver-compat.js now match the correctly anchored patterns to prevent directory traversal sequences.\n\nFurther details, including functional unit tests that demonstrate the bypasses, can be found in the GitHub security advisory, which provides comprehensive proof of concept test cases. The National Vulnerability Database (NVD) and the Common Vulnerabilities and Exposures (CVE) database have also catalogued this vulnerability for reference and tracking purposes.",
  "summary": "CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2 Vulnerability ID: CVE-2026-92951 CVSS Score: 9.9 Published: 2026-10-01 An incorrect authorization and directory traversal vulnerability in the vm2 library before version 3.11.7 allows remote attackers to bypass the sandbox's external package allowlist. This flaw permits sandboxed code to resolve and execute arbitrary…",
  "key_points": [
    "Remote attackers can bypass sandbox in vm2, execute arbitrary host code.",
    "Incorrect authorization and directory traversal in external package allowlist.",
    "Upgrade to vm2 version 3.11.7 or later to fix vulnerability."
  ],
  "editors_take": "This vulnerability forces developers to update their systems to prevent remote attackers from exploiting the vm2 library, particularly those relying on NodeVM configurations and serverless runtimes.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}