logo

Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js

ID: 201b7526-2ad4-5ae8-9e39-35f7a921fb5b

STIX ID: report--201b7526-2ad4-5ae8-9e39-35f7a921fb5b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Divya

...
...

A critical remote code execution vulnerability (CVE-2026-22709) in the vm2 npm library (≤3.10.0) permits attackers to bypass sandbox protections via Promise.prototype.then sanitization inconsistency, enabling full system compromise without authentication; users must upgrade to vm2 v3.10.2 to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.