---
id: CVE-2026-92960
title: >-
  vm2 before 3.11.6 fails to restrict access to os and dns builtins under the
  builtin: ['*'] configuration, allowing sandbox code to read host process
  identity and network topology
summary: >-
  vm2 before 3.11.6 fails to restrict access to os and dns builtins under the
  builtin: ['*'] configuration, allowing sandbox code to read host process
  identity and network topology. Attackers can invoke dns.setServers() to hijack
  the host …
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-200
vendor: patriksimek
product: vm2
affected:
  - vm2 < 3.11.6
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T15:17:01.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92960'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-m5w8-4gq2-6f8x'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vm2-before-3.11.6-process-wide-state-exposure-via-os-and-dns
    label: disclosure@vulncheck.com
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-m5w8-4gq2-6f8x'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-17T14:21:15.884585Z'
ingestedAt: '2026-09-17T14:19:30.991Z'
epss: 0.00474
epssPercentile: 0.3831
---

## Overview

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
