Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. vm2
  4. ›
  5. CVE-2026-92935

CVE-2026-92935: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE

October 1, 2026

The NodeVM constructor computes hasRealRequireConfig using typeof requireOpts === 'object' && requireOpts !== null, so require: [] bypasses the guard intended to reject nesting without an explicit require configuration. makeResolverFromLegacyOptions() then destructures the array to undefined option fields and returns a resolver containing only NESTING_OVERRIDE.vm2. Any attacker whose JavaScript is executed by a downstream NodeVM configured with {nesting: true, require: []} can load the host vm2 module, create an inner NodeVM with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in makeResolverFromLegacyOptions().

Array is converted into the vm2-only resolver: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226

Nesting loader returns the host VM constructors: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645

References

  • github.com/advisories/GHSA-8hr7-r645-pc6w
  • github.com/patriksimek/vm2/commit/05894eca1dc6a2b1a986f312c88255288a983d22
  • github.com/patriksimek/vm2/commit/54b54b74a382577f0bcd0538c5bf99acdcd7f53b
  • github.com/patriksimek/vm2/releases/tag/v3.11.7
  • github.com/patriksimek/vm2/security/advisories/GHSA-8hr7-r645-pc6w
  • nvd.nist.gov/vuln/detail/CVE-2026-92935
  • www.vulncheck.com/advisories/vm2-nodevm-remote-code-execution-via-array-shaped-require

Code Behaviors & Features

Detect and mitigate CVE-2026-92935 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.11.4 before 3.11.7

Fixed versions

  • 3.11.7

Solution

Upgrade to version 3.11.7 or above.

Impact 9 CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-913: Improper Control of Dynamically-Managed Code Resources

Source file

npm/vm2/CVE-2026-92935.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 02 Oct 2026 12:17:25 +0000.