If you still sandbox with vm2 on Node 24, bump to 3.11.7 today

By George Bailey   Published: 10/02/26   3 min read

A fresh critical sandbox escape landed in the popular Node.js library vm2 on October 1. On Node.js 24 and newer, a double-prefix trick lets untrusted code pull in node:test and break out to host shell commands. A proof of concept is public. Fixed release: 3.11.7.

If any microservice still evaluates untrusted JavaScript inside vm2, Friday’s job is a dependency bump — and a hard look at whether that sandbox should still exist at all.

A sandbox that trusts a single-stripped node: prefix is not a sandbox. It is a suggestion.

What happened

CVE-2026-92948 (GHSA-qhwx-74w5-xhxq) affects vm2 versions 3.9.6 through 3.11.6 when running on Node.js 24+. The library’s builtin blocking can be bypassed by double-prefixing a restricted module name (for example node:node:test). After a single prefix strip, the host resolves node:test. The test runner’s run() path can then pass attacker-controlled execArgv into a spawned host Node process — complete sandbox escape and host RCE. Industry scoring places it at CVSS 9.9. Fixed in vm2 3.11.7 with recursive prefix validation.

This is not the first escape class against vm2. Maintainers and researchers have repeatedly urged migration to stronger isolation (isolated-vm, containers, gVisor). Treat 3.11.7 as the emergency stop, not the long-term architecture.

Why it matters

Any SaaS feature that “safely” runs customer or plugin JavaScript inside vm2 on modern Node is one crafted payload away from host compromise. CI plugins, low-code expression engines, multi-tenant script runners, and internal tooling that still pin old vm2 are the usual blast radius.

What to do first

Forward this

If you own Node services that evaluate untrusted JS: vm2 on Node 24+ has a critical sandbox escape (CVE-2026-92948) with a public PoC. Please confirm every dependency is on 3.11.7+, that node:test is not allowlisted, and that we have a plan to leave vm2 for stronger isolation.

Details

Hunt / verify

Slack paste: vm2 CVE-2026-92948 sandbox escape on Node 24+ — bump to 3.11.7 now, strip node:test from allowlists, plan move off vm2.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.