Description
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A remote code execution flaw exists in VM2 before version 3.11.7. When the sandbox option require.external is enabled without a dedicated require.root that excludes the node_modules directory, code running inside the sandbox can load VM2’s own package. The attacker can then create an unrestricted NodeVM instance and invoke child_process to run arbitrary host operating system commands. This weakness directly grants the attacker full control over the environment in which the sandbox is executed.

Affected Systems

The affected product is VM2, packaged by patriksimek. All releases under version 3.11.7 are vulnerable; no other supported versions are listed.

Risk and Exploitability

The CVSS score of 10 classifies this as critical. The EPSS score is listed as not available, yet the lack of a specific exploitation probability does not diminish the potential impact. The vulnerability is not included in the CISA KEV catalog. Attackers can trigger the flaw by delivering crafted sandbox code that uses require.external to import VM2 packages, leading to unrestricted child_process execution. The risk remains high; immediate remediation is recommended.

Generated by OpenCVE AI on September 17, 2026 at 23:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade VM2 to version 3.11.7 or newer to eliminate the vulnerability.
  • If an upgrade cannot be performed immediately, configure the sandbox with require.root set to exclude node_modules and disable require.external.
  • Restrict sandboxed code execution by removing the ability to require VM2 packages and limiting child_process usage.

Generated by OpenCVE AI on September 17, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j3hm-6rg5-mchv vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Patriksimek
Patriksimek vm2
Vendors & Products Patriksimek
Patriksimek vm2

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.
Title vm2 before 3.11.7 Remote Code Execution via require.external
Weaknesses CWE-913
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:20:46.387Z

Reserved: 2026-09-17T12:43:03.568Z

Link: CVE-2026-92946

cve-icon Vulnrichment

Updated: 2026-09-17T19:18:12.436Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:59.963

Modified: 2026-09-17T20:18:59.483

Link: CVE-2026-92946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-913

    Improper Control of Dynamically-Managed Code Resources