OS and DNS Exposure in vm2 Versions Prior to 3.11.6
CVE-2026-92960

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92960?

The vm2 library version before 3.11.6 contains a vulnerability that allows sandbox code to circumvent access restrictions to critical built-in operations such as os and dns. This lack of restrictions can lead to unauthorized access, enabling attackers to read sensitive information about the host process and its network configuration. Specifically, through the misuse of dns.setServers(), an attacker can globally manipulate the DNS resolver of the host machine, causing all DNS queries to be redirected to a malicious server under their control. This poses significant risks for system integrity and user data confidentiality.

Affected Version(s)

vm2 0 < 3.11.6

vm2 3.11.6

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.