A flaw in the vm2 npm package allows full host remote code execution when NodeVM is created with nesting enabled but without a valid explicit require configuration. GitHub advisory GHSA-m4wx-m65x-ghrr says the bug affects vm2 versions up to and including 3.11.3 and stems from an incomplete fix for GHSA-8hg8-63c5-gwmx / CVE-2023-37903. The vulnerable logic checked only whether options.require === false before default assignment, letting attackers bypass the guard by omitting require or supplying other invalid values.
In the exposed configuration, sandboxed code can require('vm2'), create an inner NodeVM, enable access to child_process, and execute arbitrary OS commands on the host. A maintainer patch broadens the NESTING_OVERRIDE validation so any truthy nesting is rejected unless require is a non-null object or a Resolver instance, closing cases involving omitted, falsy, or truthy non-object require values. The update also adds tests to ensure malicious configurations now raise VMError while legitimate setups, including Object.create(null) and custom resolvers, continue to function.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The vm2 project patched the GHSA-m4wx-m65x-ghrr host RCE bypass in version 3.11.4. The fix addressed a flaw where enabling nesting without explicitly setting require could recreate the unsafe configuration and allow full RCE on the host.
A GitHub security advisory disclosed GHSA-m4wx-m65x-ghrr affecting vm2 versions up to and including 3.11.3, describing how omitting the require option while enabling nesting could bypass the prior fix and allow arbitrary OS command execution on the host. The advisory recommended tightening the condition around require handling to prevent the bypass.
A vm2 commit updated the NodeVM nesting guard to reject truthy nesting unless require options are a non-null object or Resolver instance, addressing a bypass of the earlier GHSA-8hg8-63c5-gwmx fix that could lead to host RCE. The change also added tests to ensure malicious configurations throw VMError while legitimate configurations still work.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.