Critical vm2 Sandbox Escape Vulnerability Allows Host System Takeover
A critical vulnerability identified as CVE-2026-92951 has been discovered in the vm2 JavaScript sandbox library. The flaw, with a CVSS score of 9.9, allows attackers to bypass the package allowlist through incorrect authorization and directory traversal. This enables sandboxed code to execute arbitrary packages on the host filesystem with full privileges. The vulnerability affects vm2 versions before 3.11.7, primarily impacting systems running untrusted code. Developers are urged to upgrade to version 3.11.7 or implement stronger isolation mechanisms.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in