This advisory has been withdrawn because it is a duplicate of GHSA-j3hm-6rg5-mchv. This link is maintained to preserve external references.
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.
{
"cwe_ids": [
"CWE-913"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:34:43Z",
"nvd_published_at": "2026-09-17T14:17:59Z",
"severity": "CRITICAL"
}