Critical vm2 sandbox flaw allows host system command execution
A critical vulnerability designated CVE-2026-92957 was published on October 1, 2026, affecting the vm2 sandbox package. The flaw exists in versions 3.11.6 and earlier of vm2's NodeVM component. It allows sandboxed code to bypass security policies and load restricted host modules like child_process. This bypass occurs due to improper handling of the 'node:' prefix in policy configuration, enabling remote code execution on the host system. The issue is fixed in version 3.11.7 of the vm2 package.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in