THREAT OPS › Threat News › [NVD] CVE-2026-92938 (CRITICAL 9.9) — vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authorit
[NVD] CVE-2026-92938 (CRITICAL 9.9) — vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authorit
CVE-2026-92938 CVSS: 9.9 CRITICAL Published: 2026-09-17T14:17:58.750
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver t
Indicators of compromise
- CVE-2026-92938cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92938