CVE-2026-93605
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance. This fork hardens `NodeVM` with a `DANGEROUS_BUILTINS` denylist that blocks host‑code‑reaching core modules **even when the sandbox requests `builtin:['*']` or names them explicitly** — the list contains `module`, `worker_threads`, `cluster`, `vm`, `repl`, `inspector`, `process`, `trace_events`, `wasi`, `diagnostics_channel`, `async_hooks`, `perf_hooks`, `v8`, `os`, `dns`, and `test`. It **omits `child_process`** — the single most direct command‑execution primitive. As a result, a sandbox running under `require:{builtin:['*']}` (or the fork's own documented `['*','-http','-net',…]` subtract pattern) can `require('child_process').execSync(...)` and execute arbitrary commands on the host. The omission is internally inconsistent: `cluster` is denied with the explicit rationale "`cluster.fork()` spawns a host child process running attacker‑controlled code," yet `child_process` — which spawns host processes more directly — is not. ### Details `lib/builtin.js`: - `DANGEROUS_BUILTINS` (lines **83‑179**) — the Set of denied builtins. `child_process` does not appear anywhere in it. - `isDangerousBuiltin(key)` (lines **185‑195**) — strips `node:` prefixes and applies family‑prefix matching against `DANGEROUS_BUILTINS`. Returns `false` for `child_process`. - `BUILTIN_MODULES` (lines **209‑210**) — the source list that the `'*'` wildcard expands to — is `builtinModules.filter(s => !s.startsWith('internal/') && !s.startsWith('_') && !isDangerousBuiltin(s))`. Because `isDangerousBuiltin('child_process')` is `false`, `child_process` **remains in `'*'`**. - `addDefaultBuiltin` (the explicit‑name path) likewise rejects only `isDangerousBuilti
Properties
- severity
- critical
- summary
- vm2 contains a sandbox escape vulnerability
- cvss_score
- 10
- retrieved_at
- 2026-10-07T22:35:46+00:00
- ghsa_published
- 2026-10-07T18:05:00Z
- source_url
- https://github.com/advisories/GHSA-pq68-rvw4-xp4r
- ghsa_updated
- 2026-10-07T18:05:01Z
- ghsa_id
- GHSA-pq68-rvw4-xp4r
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-93605
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-07T22:35:46+00:00
- is_ghsa_only
- false
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph