CVSS 9.8 Sandbox Escape: Critical vm2 Flaw Exposes Millions of Apps
ID: a7d66ce2-c3dc-5e6c-bee2-5cd453abd5a2
STIX ID: report--a7d66ce2-c3dc-5e6c-bee2-5cd453abd5a2
Feed Name: securityonline.info
A critical sandbox escape vulnerability (CVE-2026-22709, CVSS 9.8) was disclosed in the widely used vm2 Node.js library: unsanitized global Promise.prototype.then/catch allows attackers to obtain constructors via error objects, reach the Function constructor, and execute arbitrary host commands (the disclosure demonstrates loading child_process and running execSync). The flaw affects vm2 versions 3.10.0 and earlier; maintainers released a patch and users are urged to upgrade to vm2 3.10.2 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
