GHSA-c9wr-qm7p-p6vcCritical· 9.0▾ MidnightDuplicate Advisory: vm2: NodeVM custom resolution bypasses external path boundaries
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-5h3f-q97h-ccvc. This link is maintained to preserve external references.
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures require.external with a custom resolver (and context: 'host'), LegacyResolver.customResolve in lib/resolver-compat.js records the resolved module directory in this.externals as new RegExp('^' + escapeRegExp(resolvedPath)), without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. foo) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. .../node_modules/foo2/index.js); the sibling passes isPathAllowedForModule and is loaded through hostRequire, so its top-level code runs in the host process before the exports are wrapped with vm.readonly, resulting in a sandbox escape and arbitrary code execution in the host context.
vm2 < 3.12.2Upgrade to a patched release:
vm2 3.12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100721Critical· 9.0vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver
CVE-2026-92951Critical· 9.9vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation
CVE-2026-92945Medium· 4.2vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison
CVE-2026-43999Critical· 9.9vm2 is an open source vm/sandbox for Node.js
GHSA-4xmw-hh9q-4q7cCritical· 9.0Duplicate Advisory: vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
GHSA-2vh9-cv26-p97mMedium· 5.8Duplicate Advisory: vm2: util.getCallSites() bypasses GHSA-v27g host-frame redaction, leaks host call stack