{
  "id": 11356877,
  "title": "CVE-2026-92957: CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass",
  "url": "https://urgent.news/2026/10/02/cve-2026-92957-cve-2026-92957-sandbox-escape-and-remote-code",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T04:30:31.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/cverports/cve-2026-92957-cve-2026-92957-sandbox-escape-and-remote-code-execution-in-vm2-via-node-prefix-inl"
  },
  "original_language": "en",
  "account": "CVE-2026-92957 is a critical vulnerability in the vm2 sandbox package, specifically the NodeVM component, that allows sandboxed code to bypass security policies and execute arbitrary system commands. This issue affects versions of vm2 up to and including 3.11.6, with version 3.11.7 containing the necessary fix.\n\nThe vulnerability arises due to a failure in the parser to recognize exemptions in negative built-in module deny lists when using the 'node:' prefix. For example, a config like -node:child_process fails to register the exemption as expected, allowing the host's child_process module to be loaded and executed. This effectively grants the ability to run arbitrary system commands on the host system, leading to a remote code execution (RCE) scenario.\n\nAttackers can exploit this through a Proof of Concept (PoC) currently available. The CVSS score for this vulnerability is 9.9 (Critical) according to CVSS v3.1 and 9.4 (Critical) as per CVSS v4.0. This makes it one of the most serious vulnerabilities affecting the vm2 sandbox.\n\nThe exploit has not yet been publicly demonstrated, but the CVSS scores and the nature of the flaw indicate that it could be developed into a practical attack in due course. The vulnerability exists in vm2 sandbox environments, specifically those running versions 3.11.6 or earlier. The fix was introduced in version 3.11.7, where the parser now correctly normalizes the 'node:' prefix in negative deny tokens, thus preventing the silent exposure of host modules.\n\nTo mitigate this vulnerability, users are advised to upgrade to version 3.11.7 or later. Additionally, configurations that rely on wildcard require policies with negative deny tokens should be reviewed and modified. It is recommended to explicitly define a strict allowlist of required modules instead of using wildcard rules combined with exemptions. This approach helps ensure that only the necessary modules are accessible, reducing the risk of sandbox escape and RCE attacks.",
  "summary": "CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass Vulnerability ID: CVE-2026-92957 CVSS Score: 9.9 Published: 2026-10-01 A vulnerability in the NodeVM component of the vm2 sandbox package through version 3.11.6 allows sandboxed code to bypass security policies restricting access to built-in modules. When a wildcard require policy is configured with…",
  "key_points": [
    "Critical vulnerability CVE-2026-92957 allows sandbox escape and remote code execution in vm2.",
    "Upgrade to vm2 version 3.11.7 or later to mitigate the critical vulnerability."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}