This advisory has been withdrawn because it is a duplicate of GHSA-jxxv-8r27-vm4p. This link is maintained to preserve external references.
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
{
"cwe_ids": [
"CWE-453"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:38:40Z",
"nvd_published_at": "2026-09-17T14:18:00Z",
"severity": "CRITICAL"
}