Description
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array into undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. As a result, an attacker who can supply JavaScript executed by a NodeVM configured with truthy `nesting` and an array-shaped `require` (e.g. `new NodeVM({nesting: true, require: []})`) can require the host `vm2` module, create an inner NodeVM with an attacker-chosen builtin allowlist (such as `child_process`), and execute arbitrary commands with the privileges of the host Node.js process, escaping the sandbox. Outer builtin restrictions do not constrain the attacker-created inner NodeVM. This issue is fixed in vm2 3.11.7.
Published: 2026-09-17
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

In vulnerable versions of the vm2 sandbox, the NodeVM constructor evaluates the require option with a type guard that accepts an array shaped value. Providing a require value such as [] when nesting is enabled allows the resolver to be constructed with only a nesting override, giving the attacker the host vm2 module. The attacker can then create an inner NodeVM with a custom allowlist that may include powerful built‑ins like child_process, and execute arbitrary host commands, escaping the intended sandbox entirely.

Affected Systems

The vulnerability affects the npm package vm2 from patriksimek. Versions 3.11.4 through 3.11.6 inclusive are vulnerable when a NodeVM is instantiated with nesting: true and a require value shaped as an array. Later releases, starting with 3.11.7, contain the fix.

Risk and Exploitability

The flaw carries a CVSS score of 9.5, indicating critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only the ability to execute JavaScript within a NodeVM that has nesting enabled, a common scenario when running untrusted code. Once triggered, the attacker gains full control over the host Node.js process.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vm2 to version 3.11.7 or later, which includes the validation fix that blocks array‑shaped require values.
  • If upgrading immediately is not possible, reconfigure NodeVM instances to disable nesting by setting nesting to false; this prevents the attacker from creating nested NodeVMs that could escape the sandbox.
  • For environments that must use nesting, explicitly supply a proper require configuration object (for example, { external: false, builtin: ['fs'] }) and validate that it is not an array; review any code paths that could dynamically set require to an array.

Generated by OpenCVE AI on September 18, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8hr7-r645-pc6w vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array into undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. As a result, an attacker who can supply JavaScript executed by a NodeVM configured with truthy `nesting` and an array-shaped `require` (e.g. `new NodeVM({nesting: true, require: []})`) can require the host `vm2` module, create an inner NodeVM with an attacker-chosen builtin allowlist (such as `child_process`), and execute arbitrary commands with the privileges of the host Node.js process, escaping the sandbox. Outer builtin restrictions do not constrain the attacker-created inner NodeVM. This issue is fixed in vm2 3.11.7.
Title vm2 NodeVM Remote Code Execution via Array-Shaped Require
Weaknesses CWE-913
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:21:04.162Z

Reserved: 2026-09-17T12:42:34.828Z

Link: CVE-2026-92935

cve-icon Vulnrichment

Updated: 2026-09-17T18:57:26.875Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:57.810

Modified: 2026-09-17T20:18:59.093

Link: CVE-2026-92935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-913

    Improper Control of Dynamically-Managed Code Resources