logo

Five Critical vm2 Vulnerabilities Grant Instant Node.js Host RCE

ID: 3933280a-7a10-58e9-bcf7-c3230af98848

STIX ID: report--3933280a-7a10-58e9-bcf7-c3230af98848

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

This report discloses five critical vulnerabilities in the vm2 Node.js sandbox (impacting versions through 3.11.3) that permit sandboxed scripts to escape and achieve remote code execution on the host via multiple vectors (builtin denylist bypass, JSPI-backed Promise species bypass, a patch-bypass allowing nested VMs, and prototype/property manipulation). All issues carry top severity (CVSS 9.8–10.0), there are no reliable configuration mitigations, and the vendor remediation is upgrading to vm2 version 3.11.4 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.