CVE-2026-92950
### Summary The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required. ### Details The vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 <file>` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox → host boundary that vm2 is meant to enforce. #### Vulnerable code path 1. **Source** - `bin/vm2:3` → `lib/cli.js:7-18`. `process.argv[2]` is the attacker-authored script path. The CLI invokes: ```js NodeVM.file(path, { verbose: true, require: { external: true } }); ``` Without `require.root`, `require.context`, nor `require.builtin`. 2. **Hop** - `lib/nodevm.js:618-636`. `NodeVM.file` reads the file and calls `new NodeVM(options).run(body, resolvedFilename)`. 3. **Hop** - `lib/nodevm.js:335` → `lib/resolver-compat.js:205-266` (`makeResolverFromLegacyOptions`). Destructures `external:true`, `rootPaths=undefined`, `hostRequire=defaultRequire` (line 218), `context='host'` (default, line 219). Because `typeof externalOpt !== 'object'` (line 265) it returns a `CustomResolver` with `checkedRootPaths=undefined` and `pathContext = () => 'host'` (line 263). 4. **Hop** - `lib/setup-node-sandbox.js:86-123` (`requireImpl`). Sandbox `require(id)` resolves via `r
Properties
- severity
- high
- summary
- vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
- cvss_score
- 8.6
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:40:45Z
- source_url
- https://github.com/advisories/GHSA-jxxv-8r27-vm4p
- ghsa_updated
- 2026-10-01T15:40:47Z
- ghsa_id
- GHSA-jxxv-8r27-vm4p
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92950
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (6)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (3)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph