CVE-2026-92950
CVE-2026-92950 is a high-severity vulnerability with a CVSS 3.x base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-453.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- CVSS v4: 9.3
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-453
- Published:
- Last modified:
Description
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
Frequently asked questions
- What is CVE-2026-92950?
- vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
- How severe is CVE-2026-92950?
- CVE-2026-92950 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-92950 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-92950?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-92950 published?
- CVE-2026-92950 was published on 2026-09-17.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-sandbox-escape-via-cli-require
Other CWE-453 vulnerabilities
- CVE-2021-27426 — Critical (CVSS 9.8): GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the…
- CVE-2024-21411 — High (CVSS 8.8): Skype for Consumer Remote Code Execution Vulnerability
- CVE-2022-3262 — High (CVSS 8.1): A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a…
- CVE-2026-0082 — High (CVSS 7.8): In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due…
- CVE-2025-48563 — High (CVSS 7.8): In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default…
- CVE-2024-41255 — High (CVSS 7.5): filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing…