Denylist Bypass in vm2 Affects NodeVM Functionality
CVE-2026-92958

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92958?

A vulnerability in vm2 versions up to 3.11.6 allows a bypass of the builtin-module denylist feature in NodeVM. This issue arises when negative entries in the denylist are not effectively matched against subpaths, leading to the potential exposure of restricted modules such as fs/promises. As a result, sandboxed code can exploit these subpaths to interact with sensitive filesystem APIs, performing operations like file creation, writing, and executing various filesystem-related tasks. This flaw highlights a critical oversight in the denylist handling mechanism, necessitating immediate updates to version 3.11.7 or higher to mitigate these risks.

Affected Version(s)

vm2 0 < 3.11.7

vm2 3.11.7

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nasaa0x
rexpository
sangnigege
manus-use
.