logo

Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code

ID: 45726b94-ec04-5860-8ca2-ec22fced9ac0

STIX ID: report--45726b94-ec04-5860-8ca2-ec22fced9ac0

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical sandbox-escape vulnerability (CVE-2026-22709, CVSS 10.0) in the vm2 Node.js package (affecting versions ≤ 3.10.0) allows attackers to bypass sandbox isolation via Promise.prototype sanitization asymmetry, enabling arbitrary code execution (demonstrated via Function and child_process). Maintainers released vm2 3.10.2 to patch the issue; organizations should urgently inventory affected deployments and upgrade or restrict VM2 execution contexts until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.