Detect vm2 Sandbox Escape via node:sqlite Native Code Execution (CVE-2026-92938) in Microsoft Sentinel
Detects exploitation and presence of CVE-2026-92938, a critical (CVSS 9.9) sandbox escape in the vm2 JavaScript sandbox library (npm) versions >= 3.11.3 and <= 3.11.6. The vulnerability (CWE-693, Protection Mechanism Failure) allows a sandboxed plugin to break out of the vm2 isolation boundary and execute native code by abusing the Node.js experimental `node:sqlite` built-in module, which was not accounted for in vm2's host-bridge protection logic. Exploitation yields full remote code execution on the host running the sandbox. This detection surfaces vulnerable package versions in deployed/built artifacts and behavioral indicators of a sandbox escape: Node processes loading node:sqlite in contexts associated with vm2, creation of SQLite database files by sandboxed workloads, and child-process/native-module activity spawned from a vm2 host process.
MITRE ATT&CK
- Tactic
- Execution Privilege Escalation
KQL Detection Query
// vm2 sandbox escape via node:sqlite (CVE-2026-92938)
// Behavioral: Node process referencing node:sqlite and vm2, or spawning children/native loads
let vmProcs = DeviceProcessEvents
| where FileName in~ ("node", "node.exe")
| where ProcessCommandLine has "vm2" or ProcessCommandLine has "node:sqlite" or ProcessCommandLine has "sqlite";
union
(
vmProcs
| where ProcessCommandLine has "node:sqlite"
| extend Signal = "node_sqlite_in_vm2_context"
),
(
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("node", "node.exe")
| where InitiatingProcessCommandLine has "vm2"
| where FileName !in~ ("node", "node.exe")
| extend Signal = "child_process_from_vm2_host"
)
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, Signal
| sort by Timestamp desc Flags Node.js processes that reference vm2 together with node:sqlite usage, and non-node child processes spawned by a vm2 host process — both consistent with a CVE-2026-92938 sandbox escape.
Data Sources
Required Tables
False Positives & Tuning
- Legitimate applications that intentionally use node:sqlite within vm2 for approved data-processing plugins.
- Development and CI environments where Node spawns child processes as part of normal build tooling.
- Security researchers or internal red teams validating the advisory PoC in a sanctioned lab.
Other platforms for CVE-2026-92938
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Install vulnerable vm2 version
Expected signal: npm install of [email protected] and a node_modules/vm2/package.json showing version 3.11.6.
- Test 2Simulate node:sqlite usage inside a vm2 context
Expected signal: Process-creation event for node with a command line containing 'vm2' and 'node:sqlite', and creation of /tmp/vm2_escape_poc.db.
- Test 3Simulate post-escape child process from vm2 host
Expected signal: Process-creation event showing a child process (e.g. id/sh) whose parent is a node process referencing vm2.
References (6)
- https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx
- https://nvd.nist.gov/vuln/detail/CVE-2026-92938
- https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-remote-code-execution-via-node-sqlite
- https://github.com/advisories/GHSA-6w8r-xxw2-g3hx
Response Playbook
Triage
- Confirm whether the affected host runs an application that embeds the vm2 npm package; inspect package.json / package-lock.json / node_modules/vm2/package.json for a version in the range >= 3.11.3 and <= 3.11.6.
- Determine whether the application accepts and executes untrusted/third-party plugins or user-supplied code inside vm2 — this is the exploitation precondition.
- Review the flagged Node process command line and any child processes or node:sqlite usage to distinguish a legitimate plugin from an escape attempt.
- Check whether a SQLite database file was created in an unexpected path by the sandboxed workload, which can be a side effect of the exploit primitive.
Containment
- Upgrade vm2 to 3.11.7 or later (which contains fix commit aa146a77f859325e079f3bfbfe6d8309af483daa), or remove vm2 entirely in favor of a maintained isolation runtime.
- Immediately disable or quarantine untrusted plugin loading in the affected application until the patched version is deployed.
- Isolate hosts showing confirmed child-process execution originating from a vm2 host process, and rotate any credentials accessible to that process.
Evidence Collection
- Capture the Node process command line, environment, loaded modules, and full parent/child process tree for the flagged activity.
- Preserve application plugin inputs, logs, and any SQLite database files created by the sandboxed workload for forensic analysis.
- Export the resolved vm2 version from the deployed artifact and the lockfile to document exposure window.
Escalation Criteria
- !Escalate to incident response if a non-node child process was spawned by a vm2 host process or native code execution is confirmed.
- !Escalate if the vulnerable host is internet-facing or processes untrusted multi-tenant plugin code.
- !Escalate if credential access, lateral movement, or persistence follows the flagged sandbox-escape activity.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
node_modules/vm2/package.json showing an affected version. - >
Unexpected SQLite database files created by the Node/vm2 process. - >
Process-creation telemetry showing non-node children spawned by a vm2 host process. - >
Application plugin inputs/logs containing node:sqlite references or require('node:sqlite') usage.
Tuning Guidance
Baseline which applications legitimately embed vm2 and whether any approved plugins use node:sqlite; allowlist those specific process/command-line patterns. Prioritize alerts on hosts confirmed to run vm2 3.11.3–3.11.6 and those exposed to untrusted plugin input. Reduce noise from CI/build environments by excluding known build-tool subprocess chains, but keep production workloads at full sensitivity.
Hunting Queries
Hunts for non-node child processes spawned by a vm2 host process, a strong post-escape indicator of CVE-2026-92938.
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node","node.exe") | where InitiatingProcessCommandLine has "vm2" | where FileName !in~ ("node","node.exe") | project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine index=edr parent_process_name IN (node,node.exe) parent_process="*vm2*" NOT (process_name=node OR process_name=node.exe) | table _time, host, process_name, process, parent_process Atomic Red Team Tests
Pins vm2 to an affected version (3.11.6) to validate that software-inventory and version-detection controls flag the exposure.
Command
mkdir -p /tmp/vm2-cve-lab && cd /tmp/vm2-cve-lab && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "console.log(require('/tmp/vm2-cve-lab/node_modules/vm2/package.json').version)" Cleanup
rm -rf /tmp/vm2-cve-lab Expected Telemetry
npm install of [email protected] and a node_modules/vm2/package.json showing version 3.11.6.
Expected Detection
Software composition / version-based detection flags vm2 in the affected range 3.11.3–3.11.6.
Runs a Node process whose command line references vm2 and node:sqlite to exercise the behavioral command-line detection (benign, no actual escape).
Command
node --experimental-sqlite -e "process.title='vm2-plugin'; try{const s=require('node:sqlite'); const db=new s.DatabaseSync('/tmp/vm2_escape_poc.db'); console.log('node:sqlite loaded in vm2 context');}catch(e){console.log('node:sqlite not available: '+e.message);}" Cleanup
rm -f /tmp/vm2_escape_poc.db Expected Telemetry
Process-creation event for node with a command line containing 'vm2' and 'node:sqlite', and creation of /tmp/vm2_escape_poc.db.
Expected Detection
KQL/SPL/EQL rules flag node:sqlite reference in a vm2 context.
Spawns a non-node child process from a Node process tagged as a vm2 host to validate detection of the native code execution step.
Command
node -e "process.title='vm2-host'; const{execSync}=require('child_process'); console.log(execSync('id').toString());" vm2-sandbox-plugin Cleanup
echo 'no artifacts to clean' Expected Telemetry
Process-creation event showing a child process (e.g. id/sh) whose parent is a node process referencing vm2.
Expected Detection
Behavioral detection flags a non-node child process spawned by a vm2 host process.