Sandbox Escape Vulnerability in vm2 CLI Tool by vm2
CVE-2026-92950
9.3CRITICAL
What is CVE-2026-92950?
The vm2 CLI tool before version 3.11.7 is susceptible to a sandbox escape vulnerability, enabling attackers to execute arbitrary code in the host Node.js environment. By supplying a crafted script that invokes require(__filename), adversaries can bypass the sandbox's protections and gain access to sensitive host modules, including file system and child process functionalities.
Affected Version(s)
vm2 0 < 3.11.7
vm2 3.11.7
