Npm · Vm2 · CVE-2026-92946
**Name of the Vulnerable Software and Affected Versions**
vm2 versions prior to 3.11.7
**Description**
A remote code execution issue exists when `require.external` is enabled without an explicit `require.root` that excludes `node modules`. This allows sandboxed code to require the vm2 package itself, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands using `child process`.
**Recommendations**
Update to version 3.11.7 or later.
As a temporary mitigation, ensure `require.root` is explicitly configured to exclude `node modules` when `require.external` is enabled.