criticalCVSS 9.9Vulnerability

CVE-2026-92951

### Summary vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages. When `NodeVM` enables an `external` allowlist together with a custom `resolve` callback, vm2 checks the requested package name with a non-exact match. For example, if the allowlist only permits `left-pad`, an attacker can still bypass the check with a colliding package name such as `evil-left-pad`, because it contains the allowlisted name. If the colliding package already exists in a host path resolvable by the custom resolver, or if the target application's custom resolver / dependency-management workflow downloads the package and places it in a resolvable path, vm2 loads and executes that package in the host context. This lets sandboxed code bypass the module allowlist and may further lead to host code execution. ### Details `NodeVM` supports `require.external` to configure which external npm packages sandboxed code may load. It also supports a custom resolver through `require.resolve`. This combination is commonly used in business plugin systems, user-script platforms, or sandbox execution environments: the application allows only a small set of trusted dependencies while using a custom resolver that points to the application's own package directory. The vulnerability is in the allowlist pre-check logic before the custom resolver is called. vm2 generates a regular expression from the `external` allowlist and uses it to check the original package name supplied by sandboxed code. However, the regular expression is not anchored to the full package-name boundary, so it performs a substring match on the original package name. For example, with the following configuration: ```js new NodeVM({ require: { external: ['left-pad'], resolve: id => require.resolve(id, { paths: [customRoot] }), context: 'host', builtin: [] } }) ``` The intended policy is that sandboxed

Properties

severity
critical
summary
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
cvss_score
9.9
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:37:19Z
source_url
https://github.com/advisories/GHSA-c48m-32m9-vx93
ghsa_updated
2026-10-01T15:37:20Z
ghsa_id
GHSA-c48m-32m9-vx93
last_source
GitHub Advisory Database
cve_id
CVE-2026-92951
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (6)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (3)

→[Weakness]Incorrect Authorization
→[Weakness]Use of Incorrectly-Resolved Name or Reference
→[Weakness]Inclusion of Functionality from Untrusted Control Sphere

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92951 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal