logo

Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks

ID: 99372d9c-54b2-5c6f-a9ad-91470f1a7c57

STIX ID: report--99372d9c-54b2-5c6f-a9ad-91470f1a7c57

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Abinaya

...
...

The report discloses eleven critical vulnerabilities in the vm2 Node.js sandboxing library (affecting versions up to 3.11.1), several of which allow full sandbox escape and remote code execution on the host. It enumerates CVEs, affected and patched versions (two CVEs remain unpatched), describes multiple attack techniques (prototype manipulation, Promise species overwrites, WebAssembly exception handling, util.inspect and Module._load abuses), and recommends upgrading to 3.11.1 where available or replacing vm2 with kernel-level isolation (Docker, gVisor, Firecracker) and avoiding unsafe configurations such as nesting:true and wildcard built-ins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.