CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)
ID: 7f8fdd8b-21a5-5371-b72d-96a4eec76bb2
STIX ID: report--7f8fdd8b-21a5-5371-b72d-96a4eec76bb2
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-47131 — vm2 sandbox escape (CVSS 10.0):** A critical vulnerability in vm2 (<3.11.4) allows sandboxed JavaScript to use a Buffer.prototype access pattern (Buffer.call.call with __lookupGetter__/__lookupSetter__) to reach host-realm objects, obtain the host TypeError/Function constructors, and achieve full host code execution; users must upgrade to vm2 3.11.4 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
