CVE-2026-92946

Summary

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

Affected Software

VendorProductVersion RangeStatus
patriksimekvm20 < 3.11.7affected
patriksimekvm23.11.7unaffected

Weaknesses

  • CWE-913: Improper Control of Dynamically-Managed Code Resources

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References