Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js
ID: 201b7526-2ad4-5ae8-9e39-35f7a921fb5b
STIX ID: report--201b7526-2ad4-5ae8-9e39-35f7a921fb5b
Feed Name: GBHackers
Threat Score
A critical remote code execution vulnerability (CVE-2026-22709) in the vm2 npm library (≤3.10.0) permits attackers to bypass sandbox protections via Promise.prototype.then sanitization inconsistency, enabling full system compromise without authentication; users must upgrade to vm2 v3.10.2 to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
