CVE-2026-93605
published 2026-09-18CVE-2026-93605: vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other…
PriorityP268critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.73%
52.5th percentile
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| patriksimek | vm2 | < 3.12.1 | 3.12.1 |
| rhdh | red-hat-developer-hub-backstage-plugin-lightspeed-backend | — | — |
| rhdh | red-hat-developer-hub-backstage-plugin-orchestrator-backend | — | — |
| rhdh | rhdh-hub-rhel9 | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules.
ghsa_unreviewed·2026-09-18
CVE-2026-93605 [CRITICAL] CWE-693 vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules.
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
Red Hat
vm2: vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
vendor_redhat·2026-09-18·CVSS 10.0
CVE-2026-93605 [CRITICAL] CWE-184 vm2: vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
vm2: vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
A flaw was found in vm2. The sandbox environment fails to restrict access to the child_process module, which handles system command execution. In environments configured to allow built-in modules, an attacker capable of running untrusted code within the sandbox can load this module to break containment. This can result in arbitrary code execution on the underlying host system.
St
No detection rules found.
No public exploits indexed.
2026-09-18
Published