CVE-2026-92946

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo

    🔓 CVE-2026-92946: vm2 sandbox escape via `require.external` — if `require.root` isn't set, sandboxed code can require() local files and npm packages, achieving full RCE. CVSS 10. Patch now. #cybersecurity #nodejs #vulnerabilities #ciso #msp https://secalerts.co/vulnerability/GHSA-j3hm-6rg5-mchv?utm_campaign=x https://t.co/GdrgssXPji

    0000044
    894 followersView on X

Explore more