跳到正文
原文
Google AI:DEV 作者专属(RSS)· CVE Reports·· 4 小时前AI 评分55

vm2 沙箱漏洞 CVE-2026-92957:node: 前缀策略绕过导致沙箱逃逸与远程代码执行

CVE-2026-92957: CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass

AI 导读

vm2 沙箱包 3.11.6 及更早版本的 NodeVM 组件存在漏洞 CVE-2026-92957,CVSS v3.1 评分 9.9(Critical)。

正文

CVE Reports

CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass

Vulnerability ID: CVE-2026-92957
CVSS Score: 9.9
Published: 2026-10-01

A vulnerability in the NodeVM component of the vm2 sandbox package through version 3.11.6 allows sandboxed code to bypass security policies restricting access to built-in modules. When a wildcard require policy is configured with negative deny entries using the 'node:' prefix (e.g., '-node:child_process'), the parser fails to recognize the exemption due to exact string comparison. As a result, the unmitigated module is registered, allowing sandboxed code to import the host child_process module and execute arbitrary system commands.

TL;DR

vm2 fails to normalize the 'node:' prefix in negative builtin policy entries, allowing sandboxed code to load disallowed modules like 'child_process' and achieve remote code execution on the host.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-269
  • Attack Vector: Network
  • CVSS v3.1 Score: 9.9 (Critical)
  • CVSS v4.0 Score: 9.4 (Critical)
  • EPSS Score: 0.00537 (43.14th percentile)
  • Exploit Maturity: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • vm2 sandbox environments running version 3.11.6 or earlier
  • vm2: <= 3.11.6 (Fixed in: 3.11.7)

Code Analysis

Commit: b0f5066

fix(GHSA-8686-vhfx-7r3j): normalize the node: prefix on negative builtin deny tokens

@@ -12,3 +12,9 @@\n \t\t\t\tconst name = BUILTIN_MODULES[i];\n-\t\t\t\tif (builtins.indexOf(`-${name}`) === -1) {\n+\t\t\t\t// SECURITY (GHSA-8686-vhfx-7r3j): a negative deny token may be\n+\t\t\t\t// spelled with the `node:` URL prefix (`-node:child_process`),\n+\t\t\t\t// matching how `require()` accepts `node:`-prefixed specifiers.\n+\t\t\t\t// The exact-string match only recognized `-child_process`, so the\n+\t\t\t\t// `node:` spelling was a silent no-op and left the real host\n+\t\t\t\t// module exposed under `builtin: ['*']`. Match BOTH spellings.\n+\t\t\t\tif (builtins.indexOf(`-${name}`) === -1 && builtins.indexOf(`-node:${name}`) === -1) {\n \t\t\t\t\taddDefaultBuiltin(res, name, hostRequire);\n

Mitigation Strategies

  • Upgrade the vm2 package to version 3.11.7 or later to resolve the prefix normalization error.
  • Avoid wildcard configurations with negative exclusions. Instead, explicitly define a strict allowlist containing only the minimal set of required modules.
  • Migrate existing sandboxed execution flows away from vm2 to alternative isolation boundaries such as WebAssembly runtimes or containerized processes.

Remediation Steps:

  1. Identify all projects and configurations utilizing the vm2 package.
  2. Review configuration files initializing NodeVM, locating any occurrences of wildcard require policies containing negative deny tokens (e.g., 'builtin: ["*", "-node:..."]').
  3. Update package.json dependencies to target 'vm2': '^3.11.7'. Run npm install or yarn install to apply the patch.
  4. If upgrading is not immediately possible, rewrite the NodeVM options block to explicitly allow only specific safe built-in libraries (e.g., builtin: ['path', 'url']) and avoid using wildcard rules combined with exemptions.

References


Read the full report for CVE-2026-92957 on our website for more details including interactive diagrams and full exploit analysis.

来源:Google AI:DEV 作者专属(RSS) · dev.to