Bypassing vm2's External Package Allowlist: A Deep Dive into CVE-2026-92951
This educational analysis delves into the details of CVE-2026-92951, a vulnerability in the vm2 library that allows sandboxed JavaScript code to bypass the external package allowlist and execute code in the host context. We will explore the root cause, attack surface, exploitation mechanics, and real-world impact of this vulnerability, providing defensive insights for security practitioners and technical learners.