GHSA-9hxx-m5g2-2q3hCritical· 10.0▾ MidnightDuplicate Advisory: vm2 contains a sandbox escape vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-pq68-rvw4-xp4r. This link is maintained to preserve external references.
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
vm2 < 3.12.1Upgrade to a patched release:
vm2 3.12.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93605Critical· 10.0vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules
GHSA-4xmw-hh9q-4q7cCritical· 9.0Duplicate Advisory: vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
GHSA-9538-79j2-h62hHigh· 7.1Duplicate Advisory: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM
GHSA-538q-xxpg-6h4rCritical· 10.0Duplicate Advisory: vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-m7cq-7f2q-f9fhCritical· 9.9Duplicate Advisory: vm2 3.11.6 allows a sandboxed plugin to execute native code through `node:sqlite`