StackRadar

CVE-2026-92938

Critical

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 18,053 indexed, latest versions
Container images
3
deployed by those charts
Fix available
1 of 1
affected package

vm2 allows a sandboxed plugin to execute native code through `node:sqlite`

Carried by container images the latest versions of 4 of 18,053 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
vm2npm3.11.5, 3.11.63.11.73
OSV records
GHSA-6w8r-xxw2-g3hx

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-92938.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
vm2@3.11.6
3.11.7

Open the chart page →

2,319
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-92938.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
vm2@3.11.5
3.11.7

Open the chart page →

3,880
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-92938.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7

Open the chart page →

2,319
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-92938.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7

Open the chart page →

2,319

Container images carrying it

3 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7
2
n8nio/n8n:2.25.7761374d4eb84
vm2@3.11.5
3.11.7
1
n8nio/n8n:2.36.8cfe2704ff858
vm2@3.11.6
3.11.7
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.