OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100721

CRITICAL · CVSS 9 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the vm2 library prior to version 3.12.2, specifically in its NodeVM external-module resolver, allowing unauthorized access to non-allowlisted modules through an authorization bypass. This flaw enables untrusted guest code to execute arbitrary code in the host process, leading to potential sandbox escapes and severe security risks. Organizations utilizing vm2 for sandboxing untrusted code should prioritize patching to mitigate the critical risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100721
Severity
CRITICAL
CVSS
9
EPSS
0.40%

Original NVD Description

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.