highCVSS 8.6Vulnerability

CVE-2026-92950

### Summary The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required. ### Details The vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 <file>` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox → host boundary that vm2 is meant to enforce. #### Vulnerable code path 1. **Source** - `bin/vm2:3` → `lib/cli.js:7-18`. `process.argv[2]` is the attacker-authored script path. The CLI invokes: ```js NodeVM.file(path, { verbose: true, require: { external: true } }); ``` Without `require.root`, `require.context`, nor `require.builtin`. 2. **Hop** - `lib/nodevm.js:618-636`. `NodeVM.file` reads the file and calls `new NodeVM(options).run(body, resolvedFilename)`. 3. **Hop** - `lib/nodevm.js:335` → `lib/resolver-compat.js:205-266` (`makeResolverFromLegacyOptions`). Destructures `external:true`, `rootPaths=undefined`, `hostRequire=defaultRequire` (line 218), `context='host'` (default, line 219). Because `typeof externalOpt !== 'object'` (line 265) it returns a `CustomResolver` with `checkedRootPaths=undefined` and `pathContext = () => 'host'` (line 263). 4. **Hop** - `lib/setup-node-sandbox.js:86-123` (`requireImpl`). Sandbox `require(id)` resolves via `r

Properties

severity
high
summary
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
cvss_score
8.6
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:40:45Z
source_url
https://github.com/advisories/GHSA-jxxv-8r27-vm4p
ghsa_updated
2026-10-01T15:40:47Z
ghsa_id
GHSA-jxxv-8r27-vm4p
last_source
GitHub Advisory Database
cve_id
CVE-2026-92950
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (6)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (3)

→[Weakness]Initialization of a Resource with an Insecure Default
→[Weakness]Insecure Default Variable Initialization
→[Weakness]Inclusion of Functionality from Untrusted Control Sphere

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92950 (CVSS 8.6) — Ninja Signal Threat Intelligence | Ninja Signal