CyberRota Analysis
AI-GeneratedA critical remote code execution vulnerability exists in vm2 versions prior to 3.11.7, allowing attackers to execute arbitrary commands on the host operating system when `require.external` is enabled without proper restrictions on `require.root`. This flaw enables sandboxed code to instantiate an unrestricted NodeVM instance, posing significant risks to applications relying on vm2 for security. Organizations using vm2 should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.