OS and DNS Exposure in vm2 Versions Prior to 3.11.6
CVE-2026-92960
10CRITICAL
What is CVE-2026-92960?
The vm2 library version before 3.11.6 contains a vulnerability that allows sandbox code to circumvent access restrictions to critical built-in operations such as os and dns. This lack of restrictions can lead to unauthorized access, enabling attackers to read sensitive information about the host process and its network configuration. Specifically, through the misuse of dns.setServers(), an attacker can globally manipulate the DNS resolver of the host machine, causing all DNS queries to be redirected to a malicious server under their control. This poses significant risks for system integrity and user data confidentiality.
Affected Version(s)
vm2 0 < 3.11.6
vm2 3.11.6
