GHSA-29x6-9qh5-83ggCritical· 10.0▾ MidnightDuplicate Advisory: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-j3hm-6rg5-mchv. This link is maintained to preserve external references.
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.
vm2 <= 3.11.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92946Critical· 10.0vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules
GHSA-5v7w-95g5-pj6qCritical· 10.0Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
GHSA-gg6f-mhqm-f7gpCritical· 10.0Duplicate Advisory: Sandbox Escape (NodeVM)
GHSA-9fxx-mv6c-j5xpCritical· 9.0Duplicate Advisory: NodeVM nesting guard accepts array-shaped require and permits host RCE
CVE-2026-92956Critical· 10.0vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26
CVE-2026-92955Critical· 10.0vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr