logo

CVSS 9.8 Sandbox Escape: Critical vm2 Flaw Exposes Millions of Apps

ID: a7d66ce2-c3dc-5e6c-bee2-5cd453abd5a2

STIX ID: report--a7d66ce2-c3dc-5e6c-bee2-5cd453abd5a2

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical sandbox escape vulnerability (CVE-2026-22709, CVSS 9.8) was disclosed in the widely used vm2 Node.js library: unsanitized global Promise.prototype.then/catch allows attackers to obtain constructors via error objects, reach the Function constructor, and execute arbitrary host commands (the disclosure demonstrates loading child_process and running execSync). The flaw affects vm2 versions 3.10.0 and earlier; maintainers released a patch and users are urged to upgrade to vm2 3.10.2 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.