logo

Critical vm2 Vulnerabilities Enable Arbitrary Code Execution Attacks

ID: 37597d63-e3a9-55dd-a32a-a2456d632129

STIX ID: report--37597d63-e3a9-55dd-a32a-a2456d632129

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: AnuPriya

...
...

Multiple critical sandbox-escape vulnerabilities were disclosed in the widely used Node.js sandbox library vm2, enabling sandboxed code to obtain host-realm objects (e.g., Function.prototype) and execute arbitrary commands on the host (RCE). Eleven advisories/CVEs are listed with affected and patched versions; most issues have fixes in vm2 3.11.0/3.11.1 but two CVEs remained unpatched at disclosure. Public proof-of-concept exploits exist for several issues, and the report recommends immediate upgrades, monitoring for additional patches, and considering more hardened alternatives such as isolated-vm or Deno’s permission model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.