Sceawere
Vulnerability Detail
CVE-2026-100721UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
vm2 Sandbox Escape via External-Module Resolver
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 1d ago
- Vendor
- patriksimek
- Product
- vm2
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-09-27T02:17:17.547Z",
"pubdate": "2026-09-27T02:17:17.547Z",
"executiveSummary": "The vm2 library, specifically versions prior to 3.12.2, is susceptible to an authorization bypass vulnerability within the NodeVM external-module resolver.\nThis flaw allows untrusted guest code to achieve a sandbox escape, leading to arbitrary code execution within the host process context.\nThe vulnerability arises when an embedder configures 'require.external' with a custom resolver while utilizing 'context: host'.\nAn attacker can exploit this by bypassing path validation checks, allowing the loading of non-allowlisted modules that share a path prefix with authorized modules.\nThe successful execution of arbitrary code in the host process poses a critical risk, as it effectively nullifies the isolation guarantees provided by the vm2 sandbox.\nExploitation requires the ability to execute untrusted code within the NodeVM environment and specific configurations of the external module resolver.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of regex-based path validation within 'LegacyResolver.customResolve' located in 'lib/resolver-compat.js'.\nWhen a custom resolver is utilized, the 'vm2' library attempts to record resolved module directories into 'this.externals' using the pattern 'new RegExp('^' + escapeRegExp(resolvedPath))'.\nCrucially, this regular expression lacks both a mandatory directory path separator and an end-of-string anchor (or boundary check).\nBecause the regex only validates that the path begins with the allowed prefix, it creates a 'prefix injection' scenario.\nAn attacker can exploit this by requesting a module that exists as a sibling to an allowlisted module. For example, if 'foo' is allowlisted, the resolver will permit access to any path starting with the string representing 'foo'. An attacker can manipulate path resolutions to target 'foo2/index.js' if its filesystem path starts with the same character sequence as the 'foo' directory.\nThe attack flow proceeds as follows: 1) The guest code initiates a 'require' for an authorized module. 2) The resolver records the path prefix. 3) The guest code then requests an absolute path to a malicious or unauthorized sibling module that shares the authorized prefix. 4) The 'isPathAllowedForModule' check incorrectly validates the malicious path because it satisfies the loose prefix match. 5) The 'hostRequire' function is invoked to load the module into the host process.\nBecause the module is loaded via 'hostRequire', its top-level code executes directly in the host process environment before the returned exports are wrapped with 'vm.readonly'.\nThis behavior facilitates a complete sandbox breakout, as the code executes with the privileges of the host Node.js process, bypassing all intended restrictions on global objects, filesystem access, and system resources.\nThis vulnerability affects vm2 versions before 3.12.2. It does not require network exposure or authentication beyond the ability to inject code into the guest vm2 instance."
}