CVE-2026-92955

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo

    🔓 vm2 sandbox escape via __proto__ getter/setter — CVSS 10. CVE-2026-92955 allows full host compromise with no auth, no interaction. If you run vm2 in prod, treat it as critical now. #cybersecurity #nodejs #vulnerabilities #ciso https://secalerts.co/vulnerability/GHSA-88hf-g992-jg85?utm_campaign=x https://t.co/ICxZBj9iwp

    0000032
    894 followersView on X

Explore more