{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vm2--3.12.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-100721"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vm2 (\u003c 3.12.2)"],"_cs_severities":["high"],"_cs_tags":["vm2","sandbox-escape","nodejs","code-execution","memory-corruption"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-100721 identifies a critical sandbox escape vulnerability in the vm2 library (versions prior to 3.12.2). The vulnerability resides in the \u003ccode\u003eNodeVM\u003c/code\u003e external-module resolver when configured with a custom resolver and \u003ccode\u003econtext: 'host'\u003c/code\u003e. The \u003ccode\u003eLegacyResolver.customResolve\u003c/code\u003e function in \u003ccode\u003elib/resolver-compat.js\u003c/code\u003e improperly validates module paths by creating a regular expression that lacks path separators or end-of-string boundaries.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker to bypass security restrictions by providing a path that shares a prefix with an allowlisted module. For example, if 'foo' is allowlisted, an attacker can require a sibling module 'foo2' located in an absolute path that starts with the same prefix. The vulnerable resolver treats this as authorized, loading the non-allowlisted module into the host process. The top-level code of the malicious module executes before the guest exports are wrapped, enabling full host-context code execution. This is particularly dangerous for applications using vm2 to sandboxing untrusted scripts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows arbitrary code execution on the host machine hosting the Node.js application. This bypasses the intended security boundaries of the vm2 sandbox, potentially leading to full server compromise, data exfiltration, or lateral movement within the environment. Any application leveraging vm2 for processing user-supplied code is highly susceptible to this sandbox escape.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the vm2 dependency to version 3.12.2 or higher to include the fix for the resolver path validation logic.\u003c/li\u003e\n\u003cli\u003eAudit applications currently utilizing the NodeVM 'context: host' configuration and a custom 'require.external' resolver to identify potential exposure.\u003c/li\u003e\n\u003cli\u003eImplement strict path sanitization or validation wrappers if immediate library updates are not feasible, though upgrading remains the primary defense.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T05:03:54Z","date_published":"2026-09-27T05:03:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/","summary":"CVE-2026-100721 is a sandbox escape vulnerability in vm2 versions before 3.12.2, allowing untrusted guest code to execute arbitrary code in the host context via an authorization bypass in the external-module resolver.","title":"Sandbox Escape in vm2 via NodeVM Module Resolver","url":"https://feed.craftedsignal.io/briefs/2026-09-vm2-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Vm2 (\u003c 3.12.2)","version":"https://jsonfeed.org/version/1.1"}