CVE-2026-92935: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
The NodeVM constructor computes hasRealRequireConfig using typeof requireOpts === 'object' && requireOpts !== null, so require: [] bypasses the guard intended to reject nesting without an explicit require configuration. makeResolverFromLegacyOptions() then destructures the array to undefined option fields and returns a resolver containing only NESTING_OVERRIDE.vm2. Any attacker whose JavaScript is executed by a downstream NodeVM configured with {nesting: true, require: []} can load the host vm2 module, create an inner NodeVM with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in makeResolverFromLegacyOptions().
Array is converted into the vm2-only resolver: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226
Nesting loader returns the host VM constructors: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645
References
- github.com/advisories/GHSA-8hr7-r645-pc6w
- github.com/patriksimek/vm2/commit/05894eca1dc6a2b1a986f312c88255288a983d22
- github.com/patriksimek/vm2/commit/54b54b74a382577f0bcd0538c5bf99acdcd7f53b
- github.com/patriksimek/vm2/releases/tag/v3.11.7
- github.com/patriksimek/vm2/security/advisories/GHSA-8hr7-r645-pc6w
- nvd.nist.gov/vuln/detail/CVE-2026-92935
- www.vulncheck.com/advisories/vm2-nodevm-remote-code-execution-via-array-shaped-require
Code Behaviors & Features
Detect and mitigate CVE-2026-92935 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →