Sandbox Escape Vulnerability in vm2 NodeVM Affects Host Systems
CVE-2026-93605
10CRITICAL
What is CVE-2026-93605?
The vm2 NodeVM, prior to version 3.12.1, is affected by a sandbox escape issue that allows unauthorized access to child_process, a Node.js module typically restricted by the DANGEROUS_BUILTINS denylist. This vulnerability enables attackers to execute arbitrary commands on the host system if NodeVM is set up with builtin:['*'] or explicitly allows child_process. As a result, any application running on affected versions could face significant security risks, making it crucial for users to upgrade to the latest version.
Affected Version(s)
vm2 0 < 3.12.1
vm2 3.12.1
