THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-92938 (CRITICAL 9.9) — vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authorit

[NVD] CVE-2026-92938 (CRITICAL 9.9) — vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authorit

mednvdPublished 2026-09-17

CVE-2026-92938 CVSS: 9.9 CRITICAL Published: 2026-09-17T14:17:58.750

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92938