External risk intelligence

vm2 Authorization Bypass Leading to Sandbox Escape

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-100721

The vulnerability exists within the vm2 Node.js sandboxing library, which is a developer-focused software dependency. It is intended for use within applications to isolate code execution, not as a standalone, internet-facing service, appliance, or edge gateway. Exposure is strictly internal to the application logic and depends on how developers implement the library.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves a bypass in a code sandboxing technology, potentially allowing unauthorized code execution within a system. This could impact applications that use this specific sandboxing library to isolate untrusted code.

  • Issue: Code isolation can be bypassed.
  • Why remember: Unrestricted code execution is a severe risk.
  • Executive takeaway: Confirm if this technology is in use.

Attack Path

How an attacker could exploit the issue

An attacker could compromise a system by tricking a component that uses the vm2 library into executing untrusted code. This occurs when the library's external module resolver is configured in a specific way. An attacker can leverage this to bypass security controls and run arbitrary code on the host system.

  • Requires custom resolver configuration.
  • Untrusted code calls a specific module.
  • Arbitrary code execution on host.

Live Threat

Current exploitation, exposure, and threat context

When configured with a custom resolver and 'host' context, untrusted guest code could bypass authorization to execute arbitrary code in the host process. This could occur if a guest requires an allowlisted module and then an absolute path to a non-allowlisted sibling module.

  • Host process code execution.
  • Bypassing authorization checks.
  • Sandbox escape and code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the vm2 library's custom resolver could allow untrusted code to execute arbitrary commands within the host process, impacting applications that use vm2 for sandboxing. System owners and platform teams should prioritize identifying where vm2 is deployed, verifying its reachability and business criticality, and confirming the accountable application owner. Planning remediation should be risk-based, potentially involving vendor coordination for updates or implementing temporary mitigations if immediate patching is not feasible.

  • Identify accountable application owners.
  • Verify deployment and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the vm2 library and how is it used?

vm2 is a Node.js library that developers use to create a secure, isolated sandbox for running untrusted code. It is designed to prevent guest code from accessing the host system's resources or global state. You will typically find it integrated as a dependency within applications that need to execute user-provided scripts safely, rather than as a standalone server or service.

Why does CVE-2026-100721 cause a sandbox escape?

This issue is categorized as an authorization bypass (CWE-863). The vulnerability exists because the library’s custom module resolver uses an overly broad regular expression when checking if a module is allowed. Because the check lacks strict path boundaries, an attacker can trick the system into loading unauthorized code that shares a similar file path prefix, ultimately letting the guest code break out of its container and run commands in the host environment.

When does this vulnerability trigger?

The flaw only triggers if your application specifically configures the NodeVM 'require.external' setting with a custom resolver and sets the context to 'host'. If you are not using this specific, advanced configuration, the vulnerable code path is not exercised. Simply using the default vm2 settings does not inherently expose the application to this specific bypass.

How relevant is this to my infrastructure?

According to Halo Surface Signal, this vulnerability is very unlikely to present an immediate internet-facing risk because vm2 is a developer-focused software dependency. The security of your system depends entirely on how your application logic implements the library. It is not an appliance or network service that you would scan at the edge, but rather a library embedded inside your private application code.

Do I need to update my software?

Yes, you should identify all applications in your environment that rely on the vm2 library and confirm if they utilize the affected custom resolver configuration. Prioritize updating to version 3.12.2 or later to resolve the underlying path-matching error. If an immediate update is not possible, coordinate with your development team to review how untrusted code is handled and whether the 'host' context configuration can be restricted.

References