CVE-2026-92946
## Summary `NodeVM`'s `require.external` option lets sandboxed code `require()` local files and npm packages. When `require.external` is enabled and `require.root` is **not explicitly set to a path that excludes `node_modules`**, two defaults combine to fully defeat the sandbox: - `require.root` defaults to **unrestricted** — "if omitted every path is allowed." - `require.context` defaults to **`"host"`** — files loaded this way run through the **real Node.js `require()`**, not inside any vm2 sandbox. Sandboxed code can therefore `require()` a relative or absolute path to vm2's own installed package (`node_modules/vm2`), obtain the real, unwrapped `NodeVM`/`VM` classes, construct a brand-new **unrestricted** nested `NodeVM` instance, and execute arbitrary host OS commands via `child_process`. This is exploitable using **vm2's own documented "Quick Examples" configuration** in `README.md`: ```js const vm = new NodeVM({ require: { external: true, root: './', }, }); ``` `root: './'` reads as a safety restriction but, in any ordinary npm project layout, `./node_modules/vm2` sits inside that same directory tree — so the restriction does not exclude vm2 itself. An application built by following the README's quick-start guide is affected by default. ## Affected Versions All vm2 versions where `lib/resolver-compat.js`'s `makeResolverFromLegacyOptions` predates this report — confirmed present as of the current `main` (post-3.11.5, including all fixes through GHSA-8hg8-63c5-gwmx / Category 25 and GHSA-cp6g-6699-wx9c / Category 24). Neither of those prior fixes covers this code path (see Root Cause). ## Details / Root Cause `lib/resolver-compat.js`: ```js const { builtin: builtinOpt, mock: mockOpt, external: externalOpt, root: rootPaths, resolve: customResolver, customRequire: hostRequire = defaultRequire, context = 'host', // <-- defaults to 'host' strict = true, fs: fsOpt = DEFAULT_FS, } = options; ... if (!externalOpt) retu
Properties
- severity
- critical
- summary
- vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
- epss_score
- 0.00857
- cvss_score
- 10
- retrieved_at
- 2026-10-05T22:59:58+00:00
- ghsa_published
- 2026-10-05T22:34:50Z
- source_url
- https://github.com/advisories/GHSA-j3hm-6rg5-mchv
- ghsa_updated
- 2026-10-05T22:34:51Z
- ghsa_id
- GHSA-j3hm-6rg5-mchv
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-92946
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-05T22:52:21+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.56983
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph