CVE-2026-100721

CVE & Vulnerabilities · September 29, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed flaw in the vm2 sandboxing library, tracked as CVE-2026-100721, affects versions before 3.12.2 and can let untrusted sandboxed code slip past its intended module allowlist. The bug stems from the NodeVM resolver checking access by string prefix rather than a full path boundary, so guest code can reach unintended directories or packages that merely share a name prefix with an approved module. Embedders who configure a custom external-module resolver with NodeVM should upgrade to the patched release.

// source: nvd.nist.gov ↗

← Back to Blog