A disclosure reported 13 vulnerabilities in the vm2 Node.js sandbox through version 3.11.7, including seven rated CVSS 10.0. The flaws provide independent routes for untrusted JavaScript to escape the sandbox, potentially access the host Node.js process, and execute commands with its privileges. Reported attack surfaces include WebAssembly, Buffer memory, TLS configuration, module-resolution controls, Promise handling, typed-array prototypes, and NodeVM configuration validation; vm2 version 3.11.8 reportedly remediates all 13 issues. No public exploit or CISA Known Exploited Vulnerabilities listing was known at publication.
Organizations running untrusted code with vm2 should upgrade to 3.11.8, identify exposed deployments, and review whether the library is being relied on as a sole security boundary. vm2’s own security guidance warns that same-process JavaScript sandboxing is prone to newly discovered escape techniques and recommends defense in depth: avoid nesting: true and overly broad builtin-module access, enforce memory limits and buffer-allocation caps, and use separate processes, containers, VMs, or managed execution environments for fully untrusted workloads. NodeVM timeouts do not reliably stop infinite loops, and vm2 alone does not prevent all denial-of-service conditions.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-92960 was added for vm2 versions before 3.11.6, where use of builtin: ['*'] exposes the Node.js os and dns modules to sandboxed code. The flaw can expose host and network information and permit dns.setServers() calls that globally alter the host process DNS resolver configuration; CISA SSVC metadata records proof-of-concept exploitation.
A disclosure reported 13 vulnerabilities affecting vm2 releases through version 3.11.7, including seven CVSS 10.0 flaws that could enable sandbox escape and host-process access. The disclosure stated that vm2 version 3.11.8 fixes all 13 issues and that no public exploit or CISA KEV listing was known at that time.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcethreataft.com
Open sourcenpmjs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.