CVE-2026-100721 — vm2 NodeVM External Allowlist Bypass (Sandbox Escape)
September 28, 2026 · 123 views
Incorrect authorization (CWE-863) in vm2 npm before 3.12.2: NodeVM external allowlist and resolver path checks allow colliding package names (evil-left-pad) or prefix path tricks → host-context require and sandbox escape / host RCE when embedders run untrusted JS with require.external + custom resolve. CVSS 9.0/9.5 Critical. Python PoC: --lab (Node), check, remote exploit, mass -j.
Description
Overview
CVE-2026-100721 affects vm2 (npm) before 3.12.2 — incorrect authorization in the NodeVM external-module resolver, leading to sandbox escape and host-side code execution when untrusted JavaScript runs inside a misconfigured embedder.
vm2 runs untrusted JS in a sandbox within the same Node process (user-script platforms, low-code runners, online IDEs, plugin sandboxes).
| | |
|---|---|
| Affected | vm2 < 3.12.2 (path-prefix fix); related name collision 3.11.7+ |
| Fixed | vm2 ≥ 3.12.2 |
| Class | Allowlist substring match (e.g. evil-left-pad vs left-pad); resolved path prefix bypass in lib/resolver-compat.js |
| CVSS 3.1 | 9.0 Critical (S:C) |
| CVSS 4.0 | 9.5 Critical |
| Credit | Tencent Xuanwu Lab XlabAI, Atuin engine, Guannan Wang et al. |
Prerequisites (typical remote chain): App executes attacker JS in NodeVM with require.external allowlist, often context: 'host' and custom require.resolve; colliding or sibling package reachable on disk.
PoC page: https://pocbit.org/pocs/cve-2026-100721
Bundled tool (Python 3)
Members: download poc.py from this page (View exploit code).
pip install -r requirements.txt
# Local authoritative lab (Node.js + npm required)
python poc.py --lab
python poc.py -u https://app.example.com --mode check
python poc.py -u https://app.example.com --mode check --probe-exec
python poc.py --list targets.example.txt --mode check -j 12
python poc.py -u http://127.0.0.1:3000 --mode exploit \
--exec-paths /api/run,/api/eval --code-field code
python poc.py --list targets.txt --mode exploit \
--exec-paths /api/run,/api/sandbox/run -j 15
| Mode | Behavior |
|------|----------|
| --lab | Installs vulnerable vm2 in lab/, evil-left-pad → POCBIT-100721-HOST_EXEC |
| check | vm2 fingerprint, version < 3.12.2, optional --probe-exec |
| exploit | POST bypass probe JS to --exec-paths; JSONL + exploited.txt |
Remote exploit targets HTTP sandbox runners you configure; use --lab for pure library verification.
Remediation
- Upgrade vm2 ≥ 3.12.2 everywhere (lockfiles, containers).
- Avoid loading externals in host context when possible.
- Treat plugin / tenant dependency dirs as untrusted.
- Gate public “run code” APIs with auth and review.
Hunting (examples)
body="vm2"
body="/api/eval"
title="playground"
Legal and ethical use
Authorized testing only. Sandbox escape equals host compromise.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-82384critical
CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization
Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.
- Web appCVE-2026-90817critical
CVE-2026-90817 — REDCap Unauthenticated RCE (Survey __passthru / Data Import)
Unauthenticated remote code execution in REDCap ≥ 13.3.0 via public survey __passthru routing and Data Import path handling. Patched in 16.0.49, 17.3.10, and 17.4.4+. Requires a valid public survey hash (s=) for the published check/exploit tooling.
- Web appCVE-2026-41940critical
CVE-2026-41940 - WHM/cPanel Authentication Bypass Research Tool
Critical WHM/cPanel issue (CVE-2026-41940): pre-authentication bypass chain described in public research, with CVSS ~9.8. Restrict WHM exposure and patch from vendor advisories.
- Web appCVE-2026-100835critical
CVE-2026-100835 — Edgeless Contrast Remote Attestation Relay (aTLS)
Remote attestation relay (CWE-295) in Edgeless Systems Contrast before 1.16.0: cryptographically valid TEE reports matching ReferenceValues were accepted without binding to specific trusted hardware, allowing MITM relay to impersonate Coordinator or workloads in attested TLS. Fixed in 1.16.0 with AllowedChipIDs (SEV-SNP) and AllowedPIIDs (TDX). CVSS 4.0 9.1 Critical (VulnCheck). PoC audits manifests, detects versions, probes Coordinator — no MITM/TEE forgery.