PT-2026-94329 · Npm · Vm2
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
vm2 versions 2.0.0 through 3.11.6
Description
NodeVM contains a builtin-module denylist bypass. When the embedder uses the builtin wildcard with negative entries in the
require configuration, negative entries are matched by exact module name in lib/builtin.js. Consequently, an entry like -fs only removes the fs module and fails to remove builtin subpaths such as fs/promises. This allows sandboxed code to access the promise-based filesystem API by calling require('fs/promises') or require('node:fs/promises') even when fs is denied. Additionally, the node: prefix handling is inconsistent, as a -node:fs/promises entry does not block require('fs/promises'). This can lead to unauthorized host file operations, including creation and writing via fsp.writeFile(), as well as other operations such as cp, mkdir, rename, rm, rmdir, truncate, and read operations.Recommendations
Update vm2 to version 3.11.7.
Exploit
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2