criticalCVSS 10Vulnerability

CVE-2026-93605

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance. This fork hardens `NodeVM` with a `DANGEROUS_BUILTINS` denylist that blocks host‑code‑reaching core modules **even when the sandbox requests `builtin:['*']` or names them explicitly** — the list contains `module`, `worker_threads`, `cluster`, `vm`, `repl`, `inspector`, `process`, `trace_events`, `wasi`, `diagnostics_channel`, `async_hooks`, `perf_hooks`, `v8`, `os`, `dns`, and `test`. It **omits `child_process`** — the single most direct command‑execution primitive. As a result, a sandbox running under `require:{builtin:['*']}` (or the fork's own documented `['*','-http','-net',…]` subtract pattern) can `require('child_process').execSync(...)` and execute arbitrary commands on the host. The omission is internally inconsistent: `cluster` is denied with the explicit rationale "`cluster.fork()` spawns a host child process running attacker‑controlled code," yet `child_process` — which spawns host processes more directly — is not. ### Details `lib/builtin.js`: - `DANGEROUS_BUILTINS` (lines **83‑179**) — the Set of denied builtins. `child_process` does not appear anywhere in it. - `isDangerousBuiltin(key)` (lines **185‑195**) — strips `node:` prefixes and applies family‑prefix matching against `DANGEROUS_BUILTINS`. Returns `false` for `child_process`. - `BUILTIN_MODULES` (lines **209‑210**) — the source list that the `'*'` wildcard expands to — is `builtinModules.filter(s => !s.startsWith('internal/') && !s.startsWith('_') && !isDangerousBuiltin(s))`. Because `isDangerousBuiltin('child_process')` is `false`, `child_process` **remains in `'*'`**. - `addDefaultBuiltin` (the explicit‑name path) likewise rejects only `isDangerousBuilti

Properties

severity
critical
summary
vm2 contains a sandbox escape vulnerability
cvss_score
10
retrieved_at
2026-10-07T22:35:46+00:00
ghsa_published
2026-10-07T18:05:00Z
source_url
https://github.com/advisories/GHSA-pq68-rvw4-xp4r
ghsa_updated
2026-10-07T18:05:01Z
ghsa_id
GHSA-pq68-rvw4-xp4r
last_source
GitHub Advisory Database
cve_id
CVE-2026-93605
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-07T22:35:46+00:00
is_ghsa_only
false

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (2)

→[Weakness]Improper Control of Dynamically-Managed Code Resources
→[Weakness]Protection Mechanism Failure

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-93605 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal