{"id":"GHSA-9hxx-m5g2-2q3h","title":"Duplicate Advisory: vm2 contains a sandbox escape vulnerability","summary":"Duplicate Advisory: vm2 contains a sandbox escape vulnerability","severity":"critical","cvss":10,"cwe":["CWE-693"],"vendor":"vm2","product":"vm2","ecosystem":"npm","affected":["vm2 < 3.12.1"],"patched":["vm2 3.12.1"],"published":"2026-09-18","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:04:52Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9hxx-m5g2-2q3h","references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-pq68-rvw4-xp4r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93605"},{"url":"https://www.vulncheck.com/advisories/vm2-nodevm-before-3.12.1-remote-code-execution-via-child-process"},{"url":"https://github.com/advisories/GHSA-9hxx-m5g2-2q3h"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-07T18:42:20.893Z","slug":"GHSA-9hxx-m5g2-2q3h","body":"## Overview\n\n# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pq68-rvw4-xp4r. This link is maintained to preserve external references.\n\n# Original Description\nvm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.\n\n## Affected packages\n\n- `vm2 < 3.12.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vm2 3.12.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}