logo

CVE-2026-47208: vm2 General Sandbox Breakout — Arbitrary Host Execution (CVSS 10.0)

ID: 79718714-b027-5817-a4a7-40322d3af501

STIX ID: report--79718714-b027-5817-a4a7-40322d3af501

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

CVE-2026-47208 is a critical (CVSS 10.0) general sandbox breakout in the vm2 Node.js sandbox allowing sandboxed code to escape and execute arbitrary host OS commands; the four simultaneous vm2 escapes (including CVE-2026-47131/47137/47140) are patched in vm2 3.11.4 and users running vm2 < 3.11.4 — especially platforms executing untrusted code (REPLs, SaaS, CI) — should upgrade immediately or apply containment mitigations such as containerization, seccomp, Node.js experimental permissions, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.