Disclosure summary
## Summary `NodeVM`'s `require.external` option lets sandboxed code `require()` local files and npm packages. When `require.external` is enabled and `require.root` is **not explicitly set to a path that excludes `node_modules`**, two defaults combine to fully defeat the sandbox: - `require.root` defaults to **unrestricted** — "if omitted every path is allowed." - `require.context` defaults to **`"host"`** — files loaded this way run through the **real Node.js `require()`**, not inside any vm2 sandbox. Sandboxed code can therefore `require()` a relative or absolute path to vm2's own installed package (`node_modules/vm2`), obtain the real, unwrapped `NodeVM`/`VM` classes, construct a brand-new **unrestricted** nested `NodeVM` instance, and execute arbitrary host OS commands via `child_process`. This is exploitable using **vm2's own documented "Quick Examples" configuration** in `README.md`: ```js const vm = new NodeVM({ require: { external: true, root: './', }, }); ``` `root: './'` reads as a safety restriction but, in any ordinary npm project layout, `./node_modules/vm2` sits inside that same directory tree — so the restriction does not exclude vm2 itself. An application built by fo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-j3hm-6rg5-mchv
Open original source · Updated Oct 05, 2026
vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | vm2 | 3.11.7 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T18:34:50-04:00
MODIFIED 2026-10-05T18:34:51-04:00
INGESTED 2026-10-06T11:45:33-04:00