PT-2026-94317 · Npm · Vm2

·

CVE-2026-92946

·

Published

2026-08-25

·

Updated

2026-09-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.7
Description A remote code execution issue exists when require.external is enabled without an explicit require.root that excludes node modules. This allows sandboxed code to require the vm2 package itself, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands using child process.
Recommendations Update to version 3.11.7 or later. As a temporary mitigation, ensure require.root is explicitly configured to exclude node modules when require.external is enabled.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14937
CVE-2026-92946
GHSA-J3HM-6RG5-MCHV

Affected Products

Vm2