Sandbox Escape Vulnerability in vm2 NodeVM Affects Host Systems
CVE-2026-93605

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93605?

The vm2 NodeVM, prior to version 3.12.1, is affected by a sandbox escape issue that allows unauthorized access to child_process, a Node.js module typically restricted by the DANGEROUS_BUILTINS denylist. This vulnerability enables attackers to execute arbitrary commands on the host system if NodeVM is set up with builtin:['*'] or explicitly allows child_process. As a result, any application running on affected versions could face significant security risks, making it crucial for users to upgrade to the latest version.

Affected Version(s)

vm2 0 < 3.12.1

vm2 3.12.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.