logo

CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

ID: 7f8fdd8b-21a5-5371-b72d-96a4eec76bb2

STIX ID: report--7f8fdd8b-21a5-5371-b72d-96a4eec76bb2

Feed Name: CosmicBytez Labs

Threat Score
95/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

**CVE-2026-47131 — vm2 sandbox escape (CVSS 10.0):** A critical vulnerability in vm2 (<3.11.4) allows sandboxed JavaScript to use a Buffer.prototype access pattern (Buffer.call.call with __lookupGetter__/__lookupSetter__) to reach host-realm objects, obtain the host TypeError/Function constructors, and achieve full host code execution; users must upgrade to vm2 3.11.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.