CVE-2026-92938 | patriksimek vm2 up to 3.11.6 Module Resolver DatabaseSync.loadExtension sandbox

SecurityVulns

A vulnerability was found in patriksimek vm2 up to 3.11.6. It has been declared as critical. Affected by this issue is the function DatabaseSync.loadExtension of the component Module Resolver. The manipulation results in sandbox issue.

This vulnerability is known as CVE-2026-92938. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More