CVE-2026-92937 Sumo Logic CSE · Sumo

Detect vm2 3.11.6 Sandbox Escape to Host RCE via call/apply Indirection (CVE-2026-92937) in Sumo Logic CSE

Detects exploitation and presence of CVE-2026-92937, a critical (CVSS 10.0) sandbox escape in the vm2 JavaScript sandboxing library version 3.11.6. The vulnerability is a bypass of the prior GHSA-m283-3h24-438v fix: an attacker-controlled script running inside the vm2 sandbox can use Promise handler call/apply indirection to reach a host-side function reference, obtain the host Error constructor/prototype chain, and escape the sandbox to execute arbitrary code on the host with the privileges of the Node.js process (CWE-94 / CWE-693). A public PoC exists (GHSA-647f-g98j-qq25). This detection surfaces both vulnerable [email protected] installations and runtime indicators of sandbox escape such as unexpected child processes spawned by Node.js services that embed vm2.

MITRE ATT&CK

Tactic
Execution Privilege Escalation

Sumo Detection Query

Sumo Logic CSE (Sumo)
sql
_sourceCategory=*os* OR _sourceCategory=*sysmon*
| json auto nodrop
| where tolowercase(parentProcessName) matches "*node*"
| where tolowercase(processName) matches /(sh|bash|cmd\.exe|powershell|pwsh|whoami|curl|wget)$/
| count by host, parentProcessName, processName, commandLine
| sort by _count desc
critical severity medium confidence

Sumo Logic search for Node.js-parented shell/recon processes consistent with a [email protected] sandbox escape.

Data Sources

SysmonLinux auditd

Required Tables

process_events

False Positives & Tuning

  • Node CI/CD runners spawning build shells.
  • Process managers restarting Node services.
  • Node automation tools that shell out legitimately.

Other platforms for CVE-2026-92937


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Install vulnerable vm2 3.11.6

    Expected signal: File creation of node_modules/vm2/package.json with version 3.11.6; npm process execution.

  2. Test 2Simulate sandbox escape spawning a shell

    Expected signal: ProcessCreate event: parent=node, child=sh/whoami.

  3. Test 3Node spawns reconnaissance binary (Windows)

    Expected signal: Sysmon Event ID 1: ParentImage=node.exe, Image=whoami.exe.


Response Playbook

Triage

  1. Identify the affected host and confirm whether it runs a Node.js service that embeds vm2. Run `npm ls vm2` / inspect package-lock.json to confirm version 3.11.6 is present.
  2. Review the Node.js parent process command line and the spawned child process command line to determine whether the shell/recon execution is attributable to legitimate tooling (CI, pm2) or an untrusted script path.
  3. Correlate the timestamp of the suspicious child process with inbound requests to any endpoint that accepts and evaluates user-supplied JavaScript in the vm2 sandbox.
  4. Determine whether the exploited service exposes a code-evaluation feature (template engine, formula evaluator, plugin runner) reachable by untrusted input.

Containment

  1. Isolate the affected host from the network to prevent lateral movement and C2 from the escaped host context.
  2. Stop or disable the Node.js service embedding vm2 until it is upgraded to vm2 3.11.7 or migrated off the deprecated vm2 library.
  3. Rotate any credentials, tokens, or secrets accessible to the Node.js process, as a successful escape grants full host-level access.

Evidence Collection

  1. Capture the full process tree (parent Node.js process + all descendants), command lines, and environment variables at time of execution.
  2. Preserve the Node.js application logs, the vm2-executed script payloads, and the package-lock.json / node_modules/vm2/package.json showing version 3.11.6.
  3. Collect network connection logs and any files written by the escaped process for malware analysis.

Escalation Criteria

  • !Escalate to incident response immediately if any child process performed outbound network connections, credential access, or wrote executables to disk.
  • !Escalate if the exploited service is internet-facing or processes untrusted user input, as exploitation is likely rather than theoretical.
  • !Escalate to the application owner to coordinate an emergency upgrade if [email protected] is confirmed in production.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >node_modules/vm2/package.json declaring "version": "3.11.6"
  • >Process creation records showing a Node.js process as the parent of a shell or recon binary
  • >Application logs containing the sandbox-evaluated JavaScript payload leveraging Promise handler call/apply indirection

Tuning Guidance

Baseline which Node.js services legitimately spawn child shells (CI runners, pm2, deployment tooling) and exclude those parent command lines. Focus alerting on Node.js services that accept untrusted input and should never spawn OS processes. After confirming the vm2 inventory, prioritize alerts on hosts where [email protected] is installed. Suppress developer workstation noise by scoping to production segments.


Hunting Queries

Hunt for any Node.js process spawning shell or reconnaissance utilities across the fleet, scoping hosts that may run vulnerable [email protected].

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node","node.exe") | where FileName in~ ("sh","bash","cmd.exe","powershell.exe","pwsh.exe","whoami","curl","wget") | summarize count() by DeviceName, InitiatingProcessCommandLine, FileName
Hunting — SPL
spl
index=os (sourcetype=Sysmon:ProcessCreate OR sourcetype=linux_secure) | search ParentImage=*node* (Image=*sh OR Image=*bash OR Image=*powershell* OR Image=*whoami*) | stats count by host, ParentImage, Image, CommandLine

Atomic Red Team Tests

Test 1 Install vulnerable vm2 3.11.6
linux

Installs the exact vulnerable vm2 version to validate inventory/version detection.

Command

bash
mkdir -p /tmp/vm2test && cd /tmp/vm2test && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "console.log(require('/tmp/vm2test/node_modules/vm2/package.json').version)"

Cleanup

bash
rm -rf /tmp/vm2test

Expected Telemetry

File creation of node_modules/vm2/package.json with version 3.11.6; npm process execution.

Expected Detection

Inventory/version scan flags [email protected] as affected by CVE-2026-92937.

Test 2 Simulate sandbox escape spawning a shell
linux

Runs a lab-only Node.js script that uses vm2 and spawns a shell to emulate a successful host escape, exercising the process-telemetry detections.

Command

bash
cd /tmp/vm2test && node -e "const {VM}=require('vm2'); try{new VM().run('1+1')}catch(e){}; require('child_process').execSync('whoami');"

Cleanup

bash
rm -rf /tmp/vm2test

Expected Telemetry

ProcessCreate event: parent=node, child=sh/whoami.

Expected Detection

KQL/SPL/EQL process-lineage rules fire on node spawning whoami.

Test 3 Node spawns reconnaissance binary (Windows)
windows

Emulates post-escape host reconnaissance by having Node.js launch whoami on Windows.

Command

powershell
node -e "require('child_process').execSync('whoami /all')"

Cleanup

powershell
echo no cleanup required

Expected Telemetry

Sysmon Event ID 1: ParentImage=node.exe, Image=whoami.exe.

Expected Detection

Chronicle/CrowdStrike/QRadar process rules flag node.exe spawning whoami.exe.

Related Detections