Skip to finding
important · RCE — vm2

vm2 3.11.7 stopped one nested import, not host execution through allowed external modules.

Affects

vm2, an in-process Node.js library used by plugin systems, code runners, CI tools and AI applications to execute untrusted JavaScript.

The remaining path requires NodeVM with require.external enabled and an allowed root containing a helper loaded in the host context. Importing a helper that exposes child_process or equivalent authority returns a capability the outer sandbox does not constrain.

Detail and 2 sources

GitLab validated that alternate path on 3.11.7. The configuration is narrower than a default sandbox escape, but the upstream README still presents require.external with root './' and warns against relying on vm2 alone.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026