Tag
#vm2
Bypassing vm2's External Package Allowlist: A Deep Dive into CVE-2026-92951
This educational analysis delves into the details of CVE-2026-92951, a vulnerability in the vm2 library that allows sandboxed JavaScript code to bypass the external package allowlist and execute code in the host context. We will explore the root cause, attack surface, exploitation mechanics, and real-world impact of this vulnerability, providing defensive insights for security practitioners and technical learners.
vm2 CLI Sandbox Escape Vulnerability
A vulnerability in the vm2 command-line tool allows a malicious sandboxed script to execute arbitrary code in the host Node.js process, bypassing sandbox isolation. Users who run untrusted scripts with the vm2 CLI are affected. Severity: Critical
vm2 NodeVM Sandbox Escape via node:test.run() execArgv
A critical vulnerability in vm2, a popular Node.js sandboxing library, allows attackers to escape the sandbox and execute arbitrary JavaScript in the host process. This is achieved by exploiting the node:test module, which can be exposed to sandboxed code when explicitly allowed by the embedder. The vulnerability affects vm2 versions >=3.9.6 and <=3.11.5 on Node.js 24 and newer.
vm2 Buffer Alloc Limit Bypass via Buffer.concat and Buffer.from
A vulnerability in vm2 allows untrusted sandbox code to bypass the bufferAllocLimit cap, leading to a potential DoS attack. The vulnerability has a CVSS score of 8.7 and is identified as CVE-2026-47683.