Sandbox Escape Vulnerability in vm2 by npm
CVE-2026-92955

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92955?

The vm2 package prior to version 3.11.8 contains a critical flaw that enables a sandbox escape via the NodeVM component. This vulnerability allows an attacker to manipulate the host proto getters and setters using console._stdout and console._stderr. As a consequence, attackers can potentially overwrite EventEmitter.prototype.emit, allowing unauthorized execution of code within the process context. This breach effectively circumvents existing code generation restrictions, posing significant security risks.

Affected Version(s)

vm2 0 < 3.11.8

vm2 3.11.8

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c0rydoras
.