## Summary `NodeVM` blocks several dangerous Node.js builtins such as `module`, `worker_threads`, `cluster`, `vm`, `repl`, and `inspector`. However, the denylist misses `process` and `inspector/promises`. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. ## D
PoC Research
CVE-2026-47140
GHSA