---
cve: "CVE-2026-92957"
severity: "CRITICAL"
cvss: 9.4
epss: "0.5%"
vendor: "patriksimek"
kev: false
exploited: false
published: "2026-09-17 14:18:01"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T13:26:31+02:00"
---

# CVE-2026-92957

> 9.4 CRITICAL · 🧪 PoC

## Beschreibung

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-node:child_process'] } })` fails to deny the canonical `child_process` module. Sandboxed code can therefore obtain the host `child_process` builtin via `require('child_process')` or `require('node:child_process')`, gaining references to process-spawning APIs such as execSync and spawn, which is equivalent to host command-execution capability for untrusted sandbox code. Fixed in vm2 3.11.7.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-26 13:30:01
- CNA-CVSS: **9.4** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 0c5b63a228c0af88d4a0d364ab0b90df278d710e (Commit)

## BSI-Hinweise (deutsch)

- [vm2: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-2997) — _BSI-Einstufung: kritisch_
  Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.

## Referenzen

- <https://github.com/patriksimek/vm2/security/advisories/GHSA-8686-vhfx-7r3j>
- <https://www.vulncheck.com/advisories/vm2-before-3.11.7-authentication-bypass-via-node-prefix>
- <https://nvd.nist.gov/vuln/detail/CVE-2026-92957>
- <https://github.com/patriksimek/vm2/commit/b0f50662dd499ff33544bb42387958c64711af1e>
- <https://github.com/patriksimek/vm2/releases/tag/v3.11.7>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-92957) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
