← Back to search

CVE-2026-92946

10 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
The vulnerability allows remote code execution when require.external is enabled without an explicit require.root that excludes node_modules, posing a critical risk.
Exploitability
Exploitation is moderately hard as it requires specific conditions, including the presence of sandboxed code and the ability to require vm2's own package.
Blast radius
If exploited, this could lead to complete control over the host system, including execution of arbitrary commands and potential data exfiltration.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 version 3.11.7 or later.
rcevm2nodejsexternalroot

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-913

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.