SB2026082527 - Multiple vulnerabilities in vm2



SB2026082527 - Multiple vulnerabilities in vm2

Published: August 25, 2026 Updated: September 18, 2026

Security Bulletin ID SB2026082527
CSH Severity
High
Patch available
YES
Number of vulnerabilities 20
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 45% Medium 45% Low 10%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 20 vulnerabilities.


1) Improper Control of Dynamically-Managed Code Resources (CVE-ID: CVE-2026-92946)

CWE-ID: CWE-913 - Improper Control of Dynamically-Managed Code Resources

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of dynamically-managed code resources in the NodeVM require.external handling and resolver logic when loading local files or npm packages without an explicit require.root that excludes node_modules. A remote attacker can require the installed vm2 package, obtain unrestricted NodeVM or VM classes, and execute arbitrary code.

The issue arises because require.root defaults to unrestricted access and require.context defaults to host, causing loaded files to run through the real Node.js require() outside the sandbox.


2) Improper access control (CVE-ID: CVE-2026-92958)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to write files on the host filesystem.

The vulnerability exists due to improper access control in NodeVM builtin module resolution when processing sandboxed require calls with the builtin wildcard policy and negative builtin entries such as -fs. A remote user can require fs/promises or node:fs/promises to write files on the host filesystem.

Only NodeVM configurations that rely on the '*' builtin wildcard together with negative builtin entries such as -fs are affected. Negative entries are checked by exact name, so denying fs does not deny the fs/promises subpath, and node:-prefixed names are handled inconsistently.


3) Improper access control (CVE-ID: CVE-2026-92957)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in NodeVM builtin require policy handling when resolving builtin modules with node:-prefixed negative wildcard entries. A remote user can require the host child_process builtin from sandboxed code to execute arbitrary code.

Only NodeVM instances configured with a wildcard builtin policy that denies child_process using the node:-prefixed spelling are vulnerable.


4) Protection mechanism failure (CVE-ID: CVE-2026-92956)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to protection mechanism failure in the vm2 VM sandbox when processing attacker-supplied JavaScript that invokes WebAssembly.compileStreaming or WebAssembly.instantiateStreaming. A remote attacker can supply crafted JavaScript that uses a Promise species bypass to obtain host Node.js capabilities and execute arbitrary code.

The issue is reachable from a default new VM() sandbox on Node.js 26 without NodeVM, require permission, host object injection, or intentionally unsafe configuration.


5) Incorrect Resource Transfer Between Spheres (CVE-ID: CVE-2026-92952)

CWE-ID: CWE-669 - Incorrect Resource Transfer Between Spheres

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt host-visible WebStream state checks.

The vulnerability exists due to incorrect resource transfer between spheres in cross-realm symbol filtering and bridge write traps when sandbox code extracts host Node.js internal symbols from WebStream prototypes and writes them onto host objects. A remote attacker can write crafted symbol-keyed properties to corrupt host-visible WebStream state checks.

Exploitation requires a vm2 embedding where a host WebStream object and the host stream/web module object are exposed to sandbox code.


6) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-92951)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to incorrectly-resolved name handling in the NodeVM custom module resolver when processing package names against the external allowlist. A remote user can request a colliding package name that passes the allowlist pre-check to execute arbitrary code.

Exploitation requires the application to use an external package allowlist together with a custom resolve callback, and a colliding package must be present in a path resolvable by that callback.


7) Inclusion of Functionality from Untrusted Control Sphere (CVE-ID: CVE-2026-92950)

CWE-ID: CWE-829 - Inclusion of Functionality from Untrusted Control Sphere

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in the vm2 CLI NodeVM sandbox configuration when running an attacker-supplied script file. A remote attacker can supply a crafted script that re-imports itself via require(__filename) to execute arbitrary code.

User interaction is required to run the supplied script through the documented CLI.


8) Modification of assumed-immutable data (CVE-ID: CVE-2026-92949)

CWE-ID: CWE-471 - Modification of Assumed-Immutable Data

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify assumed-immutable data.

The vulnerability exists due to modification of assumed-immutable data in vm.freeze()/vm.readonly() handling of accessor-backed host object properties when processing untrusted JavaScript in new VM().run() or new NodeVM().run(). A remote attacker can obtain a host setter via Object.getOwnPropertyDescriptor() or __lookupSetter__ and invoke it directly to modify assumed-immutable data.

Exploitation requires the embedder to expose a host object with an accessor own-property through vm.freeze() or vm.readonly(). Data properties are not affected.


9) Protection mechanism failure (CVE-ID: CVE-2026-92948)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code outside the sandbox.

The vulnerability exists due to protection mechanism failure in the NodeVM builtin module handling when processing sandboxed require calls and forwarding attacker-controlled execArgv to node:test.run(). A remote user can require the host node:test module via a doubled node: prefix and pass --eval JavaScript to a spawned Node process to execute arbitrary code outside the sandbox.

Exploitation requires Node.js 24 or newer and a NodeVM configuration that explicitly allows the node:test builtin.


10) Improper isolation or compartmentalization (CVE-ID: CVE-2026-92947)

CWE-ID: CWE-653 - Improper isolation or compartmentalization

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and modify host memory.

The vulnerability exists due to improper isolation or compartmentalization in the shared Buffer pool when processing small Buffer allocations exposed to sandboxed code. A remote attacker can execute crafted sandboxed code to disclose sensitive information and modify host memory.

This issue affects environments where the Buffer object is exposed to sandboxed code by default. Small allocations created by functions such as Buffer.from() and Buffer.concat() can share the same pool with the host realm.


11) Improper Control of Dynamically-Managed Code Resources (CVE-ID: CVE-2026-92935)

CWE-ID: CWE-913 - Improper Control of Dynamically-Managed Code Resources

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands on the host system.

The vulnerability exists due to improper control of dynamically-managed code resources in the NodeVM nesting guard and resolver handling when processing JavaScript in a NodeVM configured with truthy nesting and array-shaped require options. A remote attacker can supply crafted JavaScript that loads the host vm2 module, creates an inner NodeVM with an attacker-selected builtin allowlist, and execute arbitrary commands on the host system.

Exploitation is limited to applications that enable nesting and pass a malformed array-shaped require configuration.


12) Incorrect authorization (CVE-ID: CVE-2026-92945)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access a package that was not allowlisted.

The vulnerability exists due to improper access control in isPathAllowedForModule in lib/resolver-compat.js when resolving relative requires for external modules under an allowlist. A remote user can cause an allowlisted package to load a prefix-sharing sibling package to access a package that was not allowlisted.

Exploitation requires a NodeVM deployment configured with an external module allowlist and transitive loading disabled, a prefix-sharing sibling package already present in the package layout, and a reachable code path in an allowlisted package that performs the relative require.


13) Protection mechanism failure (CVE-ID: CVE-2026-92944)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to protection mechanism failure in vm2 Promise hardening in lib/setup-sandbox.js when processing Promise.prototype.finally() on async-function Promises on Node.js 26. A remote attacker can execute crafted JavaScript inside a vm2 VM to execute arbitrary code.

The issue requires untrusted JavaScript execution inside a vm2 VM and affects the sandbox boundary by exposing the host Function constructor and process object.


14) Resource exhaustion (CVE-ID: CVE-2026-92942)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the VM timeout enforcement mechanism when processing FinalizationRegistry cleanup callbacks scheduled after VM#run() returns. A remote attacker can register a FinalizationRegistry callback that executes a busy loop outside timeout enforcement to cause a denial of service.

The issue affects sandboxed code executed with the timeout option because FinalizationRegistry and WeakRef are exposed unmodified, and the cleanup callback may be triggered later by garbage collection and block the host event loop after the original run() call has already completed.


15) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-92941)

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify the host process TLS trust store and disclose sensitive information.

The vulnerability exists due to improper access control in the NodeVM builtin loader and exposed host tls module when executing sandboxed code with the allowed tls and url builtins. A remote attacker can submit crafted code that calls tls.setDefaultCACertificates() with a host array to modify the host process TLS trust store and disclose sensitive information.

Only subsequent host-realm TLS clients that rely on the default CA list are affected, and exploitation requires a NodeVM configuration that allows the tls and url builtins.


16) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-92940)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and perform unauthorized actions.

The vulnerability exists due to exposure of a resource to the wrong sphere in https.globalAgent when handling host HTTPS requests in a NodeVM that is allowed to require https. A remote attacker can register a free event listener and observe host request options and a live TLS socket to disclose sensitive information and perform unauthorized actions.

Exploitation requires the sandbox to be able to require the https builtin, and the host must use the default HTTPS agent so that pooled connections are exposed through the shared agent.


17) Process Control (CVE-ID: CVE-2026-92939)

CWE-ID: CWE-114 - Process Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary native code.

The vulnerability exists due to process control in the generic builtin loader and exposed host crypto module when calling crypto.setEngine() on an attacker-supplied native library path from sandboxed JavaScript. A remote user can supply an untrusted plugin package containing a native library and invoke crypto.setEngine() to execute arbitrary native code.

The issue is exploitable when a NodeVM instance allows the crypto builtin, and the native library constructor executes before OpenSSL finishes validating whether the file is a usable engine.


18) Protection mechanism failure (CVE-ID: CVE-2026-92938)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary native code outside the sandbox.

The vulnerability exists due to a protection mechanism failure in the NodeVM builtin module handling for `node:sqlite` when processing sandboxed plugin code with the `node:sqlite` builtin allowed. A remote user can load a crafted native library through `DatabaseSync.loadExtension()` to execute arbitrary native code outside the sandbox.

Exploitation requires the `node:sqlite` builtin to be explicitly allowed or included through `builtin: ['*']`, and a compatible native library to already be present in the untrusted plugin package.


19) Protection mechanism failure (CVE-ID: CVE-2026-92937)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the host system.

The vulnerability exists due to a protection mechanism failure in the Promise rejection sanitization logic in lib/bridge.js when registering a rejection handler through call/apply indirection on a host Promise. A remote attacker can submit crafted JavaScript that uses Function.prototype.call or apply to bypass sanitization and execute arbitrary code on the host system.

Exploitation requires the application to evaluate attacker-controlled code with vm2, expose a host-realm Promise to the sandbox, and have that Promise reject with an Error object whose own property references a host object.


20) Information Exposure Through an Error Message (CVE-ID: CVE-2026-92936)

CWE-ID: CWE-209 - Information Exposure Through an Error Message

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive system information.

The vulnerability exists due to generation of error messages containing sensitive information in error stack formatting via the vm2 bridge when processing attacker-supplied code that triggers a host-realm syntax error. A remote attacker can read a returned error stack to disclose sensitive system information.

Default VM and NodeVM configurations are affected, and the issue exposes absolute host filesystem paths from vm2, Node.js internals, and the embedding application.


Remediation

Install update from vendor's website.

References