Detect vm2 3.11.6 Sandbox Escape to Host RCE via call/apply Indirection (CVE-2026-92937) in Google Chronicle
Detects exploitation and presence of CVE-2026-92937, a critical (CVSS 10.0) sandbox escape in the vm2 JavaScript sandboxing library version 3.11.6. The vulnerability is a bypass of the prior GHSA-m283-3h24-438v fix: an attacker-controlled script running inside the vm2 sandbox can use Promise handler call/apply indirection to reach a host-side function reference, obtain the host Error constructor/prototype chain, and escape the sandbox to execute arbitrary code on the host with the privileges of the Node.js process (CWE-94 / CWE-693). A public PoC exists (GHSA-647f-g98j-qq25). This detection surfaces both vulnerable [email protected] installations and runtime indicators of sandbox escape such as unexpected child processes spawned by Node.js services that embed vm2.
MITRE ATT&CK
- Tactic
- Execution Privilege Escalation
YARA-L Detection Query
rule vm2_sandbox_escape_cve_2026_92937 {
meta:
author = "Argus"
description = "Node.js spawning shell/recon child process indicating vm2 3.11.6 host RCE"
severity = "CRITICAL"
cve = "CVE-2026-92937"
events:
$e.metadata.event_type = "PROCESS_LAUNCH"
re.regex($e.principal.process.parent_process.file.full_path, `(?i)node(\.exe)?$`)
re.regex($e.target.process.file.full_path, `(?i)(sh|bash|cmd\.exe|powershell\.exe|pwsh|whoami|curl|wget)$`)
condition:
$e
} Chronicle YARA-L 2.0 rule detecting Node.js processes launching shell or recon binaries, a sign of vm2 sandbox escape.
Data Sources
Required Tables
False Positives & Tuning
- Node-based CI/CD runners launching shells.
- Node process managers restarting services via shell.
- Legitimate Node monitoring/automation tooling.
Other platforms for CVE-2026-92937
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Install vulnerable vm2 3.11.6
Expected signal: File creation of node_modules/vm2/package.json with version 3.11.6; npm process execution.
- Test 2Simulate sandbox escape spawning a shell
Expected signal: ProcessCreate event: parent=node, child=sh/whoami.
- Test 3Node spawns reconnaissance binary (Windows)
Expected signal: Sysmon Event ID 1: ParentImage=node.exe, Image=whoami.exe.
References (6)
- https://github.com/patriksimek/vm2/security/advisories/GHSA-647f-g98j-qq25
- https://nvd.nist.gov/vuln/detail/CVE-2026-92937
- https://github.com/patriksimek/vm2/commit/315786904c416be68ff2517b86fb9d71fa6761db
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-3.11.6-remote-code-execution-via-promise-call-apply
- https://github.com/advisories/GHSA-647f-g98j-qq25
Response Playbook
Triage
- Identify the affected host and confirm whether it runs a Node.js service that embeds vm2. Run `npm ls vm2` / inspect package-lock.json to confirm version 3.11.6 is present.
- Review the Node.js parent process command line and the spawned child process command line to determine whether the shell/recon execution is attributable to legitimate tooling (CI, pm2) or an untrusted script path.
- Correlate the timestamp of the suspicious child process with inbound requests to any endpoint that accepts and evaluates user-supplied JavaScript in the vm2 sandbox.
- Determine whether the exploited service exposes a code-evaluation feature (template engine, formula evaluator, plugin runner) reachable by untrusted input.
Containment
- Isolate the affected host from the network to prevent lateral movement and C2 from the escaped host context.
- Stop or disable the Node.js service embedding vm2 until it is upgraded to vm2 3.11.7 or migrated off the deprecated vm2 library.
- Rotate any credentials, tokens, or secrets accessible to the Node.js process, as a successful escape grants full host-level access.
Evidence Collection
- Capture the full process tree (parent Node.js process + all descendants), command lines, and environment variables at time of execution.
- Preserve the Node.js application logs, the vm2-executed script payloads, and the package-lock.json / node_modules/vm2/package.json showing version 3.11.6.
- Collect network connection logs and any files written by the escaped process for malware analysis.
Escalation Criteria
- !Escalate to incident response immediately if any child process performed outbound network connections, credential access, or wrote executables to disk.
- !Escalate if the exploited service is internet-facing or processes untrusted user input, as exploitation is likely rather than theoretical.
- !Escalate to the application owner to coordinate an emergency upgrade if [email protected] is confirmed in production.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
node_modules/vm2/package.json declaring "version": "3.11.6" - >
Process creation records showing a Node.js process as the parent of a shell or recon binary - >
Application logs containing the sandbox-evaluated JavaScript payload leveraging Promise handler call/apply indirection
Tuning Guidance
Baseline which Node.js services legitimately spawn child shells (CI runners, pm2, deployment tooling) and exclude those parent command lines. Focus alerting on Node.js services that accept untrusted input and should never spawn OS processes. After confirming the vm2 inventory, prioritize alerts on hosts where [email protected] is installed. Suppress developer workstation noise by scoping to production segments.
Hunting Queries
Hunt for any Node.js process spawning shell or reconnaissance utilities across the fleet, scoping hosts that may run vulnerable [email protected].
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node","node.exe") | where FileName in~ ("sh","bash","cmd.exe","powershell.exe","pwsh.exe","whoami","curl","wget") | summarize count() by DeviceName, InitiatingProcessCommandLine, FileName index=os (sourcetype=Sysmon:ProcessCreate OR sourcetype=linux_secure) | search ParentImage=*node* (Image=*sh OR Image=*bash OR Image=*powershell* OR Image=*whoami*) | stats count by host, ParentImage, Image, CommandLine Atomic Red Team Tests
Installs the exact vulnerable vm2 version to validate inventory/version detection.
Command
mkdir -p /tmp/vm2test && cd /tmp/vm2test && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "console.log(require('/tmp/vm2test/node_modules/vm2/package.json').version)" Cleanup
rm -rf /tmp/vm2test Expected Telemetry
File creation of node_modules/vm2/package.json with version 3.11.6; npm process execution.
Expected Detection
Inventory/version scan flags [email protected] as affected by CVE-2026-92937.
Runs a lab-only Node.js script that uses vm2 and spawns a shell to emulate a successful host escape, exercising the process-telemetry detections.
Command
cd /tmp/vm2test && node -e "const {VM}=require('vm2'); try{new VM().run('1+1')}catch(e){}; require('child_process').execSync('whoami');" Cleanup
rm -rf /tmp/vm2test Expected Telemetry
ProcessCreate event: parent=node, child=sh/whoami.
Expected Detection
KQL/SPL/EQL process-lineage rules fire on node spawning whoami.
Emulates post-escape host reconnaissance by having Node.js launch whoami on Windows.
Command
node -e "require('child_process').execSync('whoami /all')" Cleanup
echo no cleanup required Expected Telemetry
Sysmon Event ID 1: ParentImage=node.exe, Image=whoami.exe.
Expected Detection
Chronicle/CrowdStrike/QRadar process rules flag node.exe spawning whoami.exe.