CVE-2026-92938 Sumo Logic CSE · Sumo

Detect vm2 Sandbox Escape via node:sqlite Native Code Execution (CVE-2026-92938) in Sumo Logic CSE

Detects exploitation and presence of CVE-2026-92938, a critical (CVSS 9.9) sandbox escape in the vm2 JavaScript sandbox library (npm) versions >= 3.11.3 and <= 3.11.6. The vulnerability (CWE-693, Protection Mechanism Failure) allows a sandboxed plugin to break out of the vm2 isolation boundary and execute native code by abusing the Node.js experimental `node:sqlite` built-in module, which was not accounted for in vm2's host-bridge protection logic. Exploitation yields full remote code execution on the host running the sandbox. This detection surfaces vulnerable package versions in deployed/built artifacts and behavioral indicators of a sandbox escape: Node processes loading node:sqlite in contexts associated with vm2, creation of SQLite database files by sandboxed workloads, and child-process/native-module activity spawned from a vm2 host process.

MITRE ATT&CK

Tactic
Execution Privilege Escalation

Sumo Detection Query

Sumo Logic CSE (Sumo)
sql
_sourceCategory=*endpoint* (node OR "node:sqlite" OR vm2)
| where (process_name = "node" or process_name = "node.exe")
| if (process_cmdline matches "*vm2*", 1, 0) as vm2_ref
| if (process_cmdline matches "*node:sqlite*", 1, 0) as sqlite_ref
| where vm2_ref = 1 or sqlite_ref = 1
| if (vm2_ref = 1 and sqlite_ref = 1, "node_sqlite_in_vm2_context", "node_or_sqlite_ref") as signal
| fields _messagetime, host, user, process_name, process_cmdline, parent_process_name, signal
| sort by _messagetime desc
critical severity medium confidence

Flags Node processes referencing both vm2 and node:sqlite, indicative of a CVE-2026-92938 sandbox escape attempt.

Data Sources

Endpoint Detection and ResponseSysmon

Required Tables

endpoint_process_events

False Positives & Tuning

  • Legitimate vm2 plugins using node:sqlite.
  • Build/CI nodes where node spawns subprocesses.
  • Authorized PoC reproduction.

Other platforms for CVE-2026-92938


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Install vulnerable vm2 version

    Expected signal: npm install of [email protected] and a node_modules/vm2/package.json showing version 3.11.6.

  2. Test 2Simulate node:sqlite usage inside a vm2 context

    Expected signal: Process-creation event for node with a command line containing 'vm2' and 'node:sqlite', and creation of /tmp/vm2_escape_poc.db.

  3. Test 3Simulate post-escape child process from vm2 host

    Expected signal: Process-creation event showing a child process (e.g. id/sh) whose parent is a node process referencing vm2.


Response Playbook

Triage

  1. Confirm whether the affected host runs an application that embeds the vm2 npm package; inspect package.json / package-lock.json / node_modules/vm2/package.json for a version in the range >= 3.11.3 and <= 3.11.6.
  2. Determine whether the application accepts and executes untrusted/third-party plugins or user-supplied code inside vm2 — this is the exploitation precondition.
  3. Review the flagged Node process command line and any child processes or node:sqlite usage to distinguish a legitimate plugin from an escape attempt.
  4. Check whether a SQLite database file was created in an unexpected path by the sandboxed workload, which can be a side effect of the exploit primitive.

Containment

  1. Upgrade vm2 to 3.11.7 or later (which contains fix commit aa146a77f859325e079f3bfbfe6d8309af483daa), or remove vm2 entirely in favor of a maintained isolation runtime.
  2. Immediately disable or quarantine untrusted plugin loading in the affected application until the patched version is deployed.
  3. Isolate hosts showing confirmed child-process execution originating from a vm2 host process, and rotate any credentials accessible to that process.

Evidence Collection

  1. Capture the Node process command line, environment, loaded modules, and full parent/child process tree for the flagged activity.
  2. Preserve application plugin inputs, logs, and any SQLite database files created by the sandboxed workload for forensic analysis.
  3. Export the resolved vm2 version from the deployed artifact and the lockfile to document exposure window.

Escalation Criteria

  • !Escalate to incident response if a non-node child process was spawned by a vm2 host process or native code execution is confirmed.
  • !Escalate if the vulnerable host is internet-facing or processes untrusted multi-tenant plugin code.
  • !Escalate if credential access, lateral movement, or persistence follows the flagged sandbox-escape activity.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >node_modules/vm2/package.json showing an affected version.
  • >Unexpected SQLite database files created by the Node/vm2 process.
  • >Process-creation telemetry showing non-node children spawned by a vm2 host process.
  • >Application plugin inputs/logs containing node:sqlite references or require('node:sqlite') usage.

Tuning Guidance

Baseline which applications legitimately embed vm2 and whether any approved plugins use node:sqlite; allowlist those specific process/command-line patterns. Prioritize alerts on hosts confirmed to run vm2 3.11.3–3.11.6 and those exposed to untrusted plugin input. Reduce noise from CI/build environments by excluding known build-tool subprocess chains, but keep production workloads at full sensitivity.


Hunting Queries

Hunts for non-node child processes spawned by a vm2 host process, a strong post-escape indicator of CVE-2026-92938.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node","node.exe") | where InitiatingProcessCommandLine has "vm2" | where FileName !in~ ("node","node.exe") | project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine
Hunting — SPL
spl
index=edr parent_process_name IN (node,node.exe) parent_process="*vm2*" NOT (process_name=node OR process_name=node.exe) | table _time, host, process_name, process, parent_process

Atomic Red Team Tests

Test 1 Install vulnerable vm2 version
linux

Pins vm2 to an affected version (3.11.6) to validate that software-inventory and version-detection controls flag the exposure.

Command

bash
mkdir -p /tmp/vm2-cve-lab && cd /tmp/vm2-cve-lab && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "console.log(require('/tmp/vm2-cve-lab/node_modules/vm2/package.json').version)"

Cleanup

bash
rm -rf /tmp/vm2-cve-lab

Expected Telemetry

npm install of [email protected] and a node_modules/vm2/package.json showing version 3.11.6.

Expected Detection

Software composition / version-based detection flags vm2 in the affected range 3.11.3–3.11.6.

Test 2 Simulate node:sqlite usage inside a vm2 context
linux

Runs a Node process whose command line references vm2 and node:sqlite to exercise the behavioral command-line detection (benign, no actual escape).

Command

bash
node --experimental-sqlite -e "process.title='vm2-plugin'; try{const s=require('node:sqlite'); const db=new s.DatabaseSync('/tmp/vm2_escape_poc.db'); console.log('node:sqlite loaded in vm2 context');}catch(e){console.log('node:sqlite not available: '+e.message);}"

Cleanup

bash
rm -f /tmp/vm2_escape_poc.db

Expected Telemetry

Process-creation event for node with a command line containing 'vm2' and 'node:sqlite', and creation of /tmp/vm2_escape_poc.db.

Expected Detection

KQL/SPL/EQL rules flag node:sqlite reference in a vm2 context.

Test 3 Simulate post-escape child process from vm2 host
linux

Spawns a non-node child process from a Node process tagged as a vm2 host to validate detection of the native code execution step.

Command

bash
node -e "process.title='vm2-host'; const{execSync}=require('child_process'); console.log(execSync('id').toString());" vm2-sandbox-plugin

Cleanup

bash
echo 'no artifacts to clean'

Expected Telemetry

Process-creation event showing a child process (e.g. id/sh) whose parent is a node process referencing vm2.

Expected Detection

Behavioral detection flags a non-node child process spawned by a vm2 host process.

Related Detections