Vulnerability Description
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-pq68-rvw4-xp4r
- https://www.vulncheck.com/advisories/vm2-nodevm-before-3.12.1-remote-code-execut
FAQ
What is CVE-2026-93605?
CVE-2026-93605 is a vulnerability with a CVSS score of 10.0 (CRITICAL). vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require c...
How severe is CVE-2026-93605?
CVE-2026-93605 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-93605?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.