GHSA-hc6q-4vvg-jf79Critical· 8.6▾ MidnightDuplicate Advisory: vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-jxxv-8r27-vm4p. This link is maintained to preserve external references.
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
vm2 <= 3.11.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92950High· 8.6vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process
GHSA-xq74-c7jx-8w5jCritical· 10.0Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store
GHSA-8mvv-mcc3-xwhhLow· 4.2Duplicate Advisory: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
GHSA-6jgm-4w45-vh8jCritical· 9.9Duplicate Advisory: vm2 crypto builtin loads attacker native code through setEngine
GHSA-hwr5-cm8v-c76qCritical· 9.8Duplicate Advisory: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-3f84-vwv5-r42gCritical· 10.0Duplicate Advisory: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection