CVE-2026-100721

LOWCVSS 9.5 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-28)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-27: 1Mentions · 2026-09-28: 209-2709-28
Referenced assets2 URLs
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 vm2'de kritik Sandbox Escape açığı Node.js için kullanılan vm2 sandbox kütüphanesinde CVE-2026-100721 keşfedildi. CVSS 4.0: 9.5 Critical require.external ile custom resolver kullanılan belirli NodeVM yapılandırmalarında authorization bypass, sandbox escape ve host üzerinde arbitrary code execution (RCE) mümkün olabiliyor. Etkilenen: vm2 < 3.12.2 Düzeltilen: vm2 3.12.2 vm2 kullanan uygulamalarda sürüm kontrolü ve 3.12.2+ güncellemesi öneriliyor.

    00030268
    2.4K followersView on X
  • Severity Daily@severitydaily

    npm audit calls vm2 3.12.1 clean. The database it reads has had no vm2 advisory since August 14. Three CVEs published overnight say that release has two 10.0 sandbox escapes. No exploitation reported. https://severitydaily.com/vm2-cve-2026-100721-npm-audit-no-advisory-since-august-14/

    2001055
    25 followersView on X
  • mürrez@murrezsec

    New on PoCbit: CVE-2026-100721 — misconfigured vm2 NodeVM + require.external can load colliding package names or path-prefix siblings in host context 📷https://pocbit.org/pocs/cve-2026-100721 Authorized testing only 🔒 #Sandbox #DevSecOps #SupplyChain #Infosec

    0001029
    619 followersView on X

Explore more