CVE-2026-100721 Details
Description
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.
A vulnerability exists in vm2 versions prior to 3.12.2, allowing for an authorization bypass in the NodeVM external-module resolver. When an embedder sets 'require.external' with a custom resolver and 'context: host', the 'LegacyResolver.customResolve' function records the resolved module directory in 'this.externals' as a regular expression matching the start of the path. This implementation lacks necessary path boundaries, enabling untrusted guest code to require an allowlisted module and then access a non-allowlisted sibling module that shares the same path prefix. The sibling module can then be loaded through 'hostRequire', executing its code in the host process and escaping the sandbox, leading to arbitrary code execution in the host context.
Users can upgrade to vm2 version 3.12.2 or later, where this vulnerability has been patched. The patch involves updating the 'LegacyResolver' to require a path boundary after the module name, preventing the unintentional loading of sibling modules that could escape the sandbox.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vm2 | <= 3.12.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion