POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-100721 — vm2 NodeVM External Allowlist Bypass (Sandbox Escape)

September 28, 2026 · 123 views

Incorrect authorization (CWE-863) in vm2 npm before 3.12.2: NodeVM external allowlist and resolver path checks allow colliding package names (evil-left-pad) or prefix path tricks → host-context require and sandbox escape / host RCE when embedders run untrusted JS with require.external + custom resolve. CVSS 9.0/9.5 Critical. Python PoC: --lab (Node), check, remote exploit, mass -j.

#nodejs#vm2#sandbox#sandbox-escape#npm#javascript#rce#authorization-bypass

CVE:

CVE-2026-100721

Date:

2026-09-28

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-100721 affects vm2 (npm) before 3.12.2 — incorrect authorization in the NodeVM external-module resolver, leading to sandbox escape and host-side code execution when untrusted JavaScript runs inside a misconfigured embedder.

vm2 runs untrusted JS in a sandbox within the same Node process (user-script platforms, low-code runners, online IDEs, plugin sandboxes).

| | | |---|---| | Affected | vm2 < 3.12.2 (path-prefix fix); related name collision 3.11.7+ | | Fixed | vm2 ≥ 3.12.2 | | Class | Allowlist substring match (e.g. evil-left-pad vs left-pad); resolved path prefix bypass in lib/resolver-compat.js | | CVSS 3.1 | 9.0 Critical (S:C) | | CVSS 4.0 | 9.5 Critical | | Credit | Tencent Xuanwu Lab XlabAI, Atuin engine, Guannan Wang et al. |

Prerequisites (typical remote chain): App executes attacker JS in NodeVM with require.external allowlist, often context: 'host' and custom require.resolve; colliding or sibling package reachable on disk.

PoC page: https://pocbit.org/pocs/cve-2026-100721

Bundled tool (Python 3)

Members: download poc.py from this page (View exploit code).

pip install -r requirements.txt

# Local authoritative lab (Node.js + npm required)
python poc.py --lab

python poc.py -u https://app.example.com --mode check
python poc.py -u https://app.example.com --mode check --probe-exec
python poc.py --list targets.example.txt --mode check -j 12

python poc.py -u http://127.0.0.1:3000 --mode exploit \
  --exec-paths /api/run,/api/eval --code-field code

python poc.py --list targets.txt --mode exploit \
  --exec-paths /api/run,/api/sandbox/run -j 15

| Mode | Behavior | |------|----------| | --lab | Installs vulnerable vm2 in lab/, evil-left-pad → POCBIT-100721-HOST_EXEC | | check | vm2 fingerprint, version < 3.12.2, optional --probe-exec | | exploit | POST bypass probe JS to --exec-paths; JSONL + exploited.txt |

Remote exploit targets HTTP sandbox runners you configure; use --lab for pure library verification.

Remediation

  1. Upgrade vm2 ≥ 3.12.2 everywhere (lockfiles, containers).
  2. Avoid loading externals in host context when possible.
  3. Treat plugin / tenant dependency dirs as untrusted.
  4. Gate public “run code” APIs with auth and review.

Hunting (examples)

body="vm2"
body="/api/eval"
title="playground"

Legal and ethical use

Authorized testing only. Sandbox escape equals host compromise.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →