{"id":"GHSA-6w8r-xxw2-g3hx","summary":"vm2 allows a sandboxed plugin to execute native code through `node:sqlite`","details":"### Summary\n\nvm2 3.11.6 exposes Node.js's host `node:sqlite` module to `NodeVM` code when that builtin is allowed explicitly or through `builtin: ['*']`. The module is wrapped as read-only, but callable methods retain host-process authority. A sandboxed plugin can construct an in-memory database with extension loading enabled and call `DatabaseSync.loadExtension()` on a native library bundled in the plugin directory.\n\nSQLite loads the library into the Node.js host process and invokes its native extension entry point. This gives the untrusted plugin arbitrary native code execution outside the sandbox.\n\nThe exploit needs only the `node:sqlite` builtin and a compatible native library already present in the untrusted plugin package. It does not require `fs`, `process`, `module`, `child_process`, `worker_threads`, `vm`, `inspector`, vm2 nesting, or an existing database file.\n\n### Details\n\nThe vulnerable boundary spans the builtin inventory, resolver, runtime loader, and generic read-only wrapper.\n\nOn current Node.js versions, the builtin inventory contains the literal name `node:sqlite`. vm2 admits that name when it is explicitly configured or when the wildcard allowlist is expanded:\n\n```js\nconst BUILTIN_MODULES = module.builtinModules.filter(/* denylist checks */);\n```\n\nThe resolver then treats every request beginning with `node:` as a core-module request, even if the complete request string is not an allowlist key:\n\n```js\nif (x.startsWith('node:') || this.builtins.has(x)) {\n  return x;\n}\n```\n\nThe sandbox runtime removes exactly one `node:` prefix and looks up the remainder in the configured builtin map:\n\n```js\nif (filename.startsWith('node:')) {\n  id = filename.slice(5);\n  return loadBuiltinModule(id);\n}\n```\n\nConsequently, the sandbox spelling below resolves to the configured map entry `node:sqlite`:\n\n```js\nrequire('node:node:sqlite')\n```\n\nThe default builtin loader imports the real module in the host realm and exposes it through `vm.readonly()`:\n\n```js\nbuiltins.set(key, vm =\u003e vm.readonly(hostRequire(key)));\n```\n\nRead-only wrapping prevents property assignment. It does not remove dangerous callable capabilities. Calls to `DatabaseSync` and `loadExtension()` are forwarded to the host implementation.\n\nThe complete exploit flow is:\n\n```text\nattacker supplies an untrusted plugin package containing JavaScript and a native library\n  -\u003e host runs the JavaScript in NodeVM with node:sqlite allowed\n  -\u003e plugin resolves the host module as node:node:sqlite\n  -\u003e plugin creates an in-memory DatabaseSync with allowExtension enabled\n  -\u003e plugin derives the bundled library path from its own __dirname\n  -\u003e plugin calls database.loadExtension(libraryPath)\n  -\u003e vm2 forwards the call to host SQLite\n  -\u003e SQLite loads the library into the Node.js host process\n  -\u003e SQLite invokes the library's native extension entry point\n  -\u003e attacker native code executes with the host process's privileges\n```\n\nThe path does not need to be read through a sandboxed filesystem API. CommonJS already supplies the plugin's own directory, so an attacker can concatenate `__dirname` with the known name of a bundled library. The host necessarily places the untrusted plugin package on disk before evaluating its JavaScript.\n\n### PoC\n\nThe attached PoC is local and harmless. Its native extension entry point writes one marker file and returns success. It does not launch a process, connect to a network service, or modify any other file.\n\nPrerequisites: macOS, Node.js with `node:sqlite`, npm, and a C compiler.\n\n1. Open the attached `poc` directory.\n2. Install the exact affected package:\n\n   ```bash\n   npm install --ignore-scripts\n   ```\n\n3. Compile and run the proof:\n\n   ```bash\n   npm run poc\n   ```\n\nThe script compiles `extension_probe.c` as `libvm2_sqlite_probe.dylib`, then runs `untrusted-plugin.js` in this restrictive configuration:\n\n```js\nnew NodeVM({\n  console: 'off',\n  require: { builtin: ['node:sqlite'] },\n});\n```\n\nThe sandboxed plugin performs only:\n\n```js\nconst { DatabaseSync } = require('node:node:sqlite');\nconst database = new DatabaseSync(':memory:', { allowExtension: true });\ndatabase.loadExtension(__dirname + '/libvm2_sqlite_probe.dylib');\ndatabase.close();\n```\n\nA vulnerable result is:\n\n```json\n{\n  \"sandboxResult\": {\n    \"nativeExtensionLoaded\": true,\n    \"usedOnlySQLiteBuiltin\": true\n  },\n  \"markerExists\": true,\n  \"markerText\": \"VM2_SQLITE_EXTENSION_ENTRYPOINT_EXECUTED\"\n}\n```\n\nThe marker is written from the compiled native extension entry point, not from JavaScript. `loadExtension()` also returns successfully, proving that SQLite both loaded the library and invoked its entry point.\n\n### Impact\n\nThis is a sandbox escape to arbitrary native code execution. The native code runs inside the Node.js host process with the operating-system identity and privileges of that process, beyond all vm2 JavaScript, module, and proxy restrictions.\n\nAn attacker can replace the marker-only extension with native code that:\n\n- reads application secrets, credentials, environment variables, and files available to the host account;\n- modifies application data or executable files and establishes persistence;\n- accesses internal services using the host's network identity;\n- steals other tenants' data from the same process;\n- terminates or corrupts the host process; and\n- performs any other operating-system action permitted to the host account.\n\nThe realistic affected workflow is a plugin platform, automation service, notebook, build service, or multi-tenant code runner that stores attacker-supplied package contents and evaluates the package's JavaScript in `NodeVM` while allowing `node:sqlite` or all builtins. The attacker does not need pre-existing host execution, a writable database, or a command-execution builtin.","aliases":["CVE-2026-92938"],"modified":"2026-10-01T15:45:07.605417287Z","published":"2026-10-01T15:29:04Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-693"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-01T15:29:04Z"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-6w8r-xxw2-g3hx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92938"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/aa146a77f859325e079f3bfbfe6d8309af483daa"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-3.11.3-through-3.11.6-remote-code-execution-via-node-sqlite"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.11.3"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6w8r-xxw2-g3hx/GHSA-6w8r-xxw2-g3hx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}