logo

5.7 Million Users at Risk: Multiple 9.8 CVSS Breakthroughs Enable Remote Code Execution in vm2 Sandbox

ID: 510c4ded-0898-5d5b-8a81-d259c2e8be73

STIX ID: report--510c4ded-0898-5d5b-8a81-d259c2e8be73

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Ddos

...
...

The report discloses several critical sandbox escape vulnerabilities in the widely used vm2 Node.js library (over 5.7M monthly downloads) — multiple CVEs rated CVSS 9.8 that enable remote code execution, including a sophisticated WASM-based escape affecting Node.js v25; maintainers have issued patches and users are strongly urged to upgrade to vm2 3.11.0 (and at least 3.10.5 for Node.js v25).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.