Disclosure summary
### Summary The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required. ### Details The vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 ` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox → host boundary that vm2 is meant to enforce. #### Vulnerable code path 1. **Source** - `bin/vm2:3` → `lib/cli.js:7-18`. `process.argv[2]` is the attacker-authored script path. The CLI invokes: ```js NodeVM.fi
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-jxxv-8r27-vm4p
Open original source · Updated Oct 01, 2026
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | vm2 | 3.11.7 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-01T11:40:45-04:00
MODIFIED 2026-10-01T11:40:47-04:00
INGESTED 2026-10-06T11:45:02-04:00