CVE-2026-92950
HIGHDescription
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
Is your site exposed to CVE-2026-92950?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-92950? +
How severe is CVE-2026-92950? +
How do I check if I'm vulnerable to CVE-2026-92950? +
Related Vulnerabilities
Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s …
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT …
Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) …
Skype for Consumer Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead …