vm2 CVE-2026-100721: path allowlist bypassed by prefix match
A vm2 sandbox authorization flaw, CVE-2026-100721, scored 9.5 under CVSS 4.0: the path allowlist matched a raw string prefix with no boundary, so an allowlisted module foo authorized its sibling foo2. The fix shipped in 3.12.2 on Sep 8; only PoC exploitation is known.
- CVE-2026-100721 scores 9.5 under CVSS 4.0 and 9.0 under 3.1
- Cause: regex '^' + path with no separator or end anchor
- Fixed in vm2 3.12.2 on Sep 8 with no API changes
- Only setups using require.external with a custom resolver are exposed
Read next
Security