CVE-2026-92948: CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

Chronological Source Flow
Back

AI Fusion Summary

Two critical vulnerabilities affect the vm2 library. CVE-2026-92948, with a CVSS score of 9.9, allows a sandbox escape via double-prefixing restricted modules like node:node:test on Node.js 24, enabling arbitrary shell command execution. Meanwhile, CVE-2026-92940, scoring 10.0, permits sandboxed code to access http.globalAgent and https.globalAgent singletons. This allows attackers to intercept host-realm network requests, capture sensitive Authorization headers, and hijack active TLSSocket streams, compromising the host process security and sensitive data.
Community Comments
Loading updates...
0