Security Advisory

CVE-2026-93605

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-18 13:20:14
Last updated 2026-09-18 13:20:14
Assigner VulnCheck
CVSS score 10.0
State PUBLISHED

Description

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.