criticalCVSS 9.9Vulnerability

CVE-2026-92938

### Summary vm2 3.11.6 exposes Node.js's host `node:sqlite` module to `NodeVM` code when that builtin is allowed explicitly or through `builtin: ['*']`. The module is wrapped as read-only, but callable methods retain host-process authority. A sandboxed plugin can construct an in-memory database with extension loading enabled and call `DatabaseSync.loadExtension()` on a native library bundled in the plugin directory. SQLite loads the library into the Node.js host process and invokes its native extension entry point. This gives the untrusted plugin arbitrary native code execution outside the sandbox. The exploit needs only the `node:sqlite` builtin and a compatible native library already present in the untrusted plugin package. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, vm2 nesting, or an existing database file. ### Details The vulnerable boundary spans the builtin inventory, resolver, runtime loader, and generic read-only wrapper. On current Node.js versions, the builtin inventory contains the literal name `node:sqlite`. vm2 admits that name when it is explicitly configured or when the wildcard allowlist is expanded: ```js const BUILTIN_MODULES = module.builtinModules.filter(/* denylist checks */); ``` The resolver then treats every request beginning with `node:` as a core-module request, even if the complete request string is not an allowlist key: ```js if (x.startsWith('node:') || this.builtins.has(x)) { return x; } ``` The sandbox runtime removes exactly one `node:` prefix and looks up the remainder in the configured builtin map: ```js if (filename.startsWith('node:')) { id = filename.slice(5); return loadBuiltinModule(id); } ``` Consequently, the sandbox spelling below resolves to the configured map entry `node:sqlite`: ```js require('node:node:sqlite') ``` The default builtin loader imports the real module in the host realm and exposes it through `vm.readonly()`: ```js builtins.set(ke

Properties

severity
critical
summary
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
cvss_score
9.9
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:29:04Z
source_url
https://github.com/advisories/GHSA-6w8r-xxw2-g3hx
ghsa_updated
2026-10-01T15:29:06Z
ghsa_id
GHSA-6w8r-xxw2-g3hx
last_source
GitHub Advisory Database
cve_id
CVE-2026-92938
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Protection Mechanism Failure

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92938 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal