CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)
ID: ce667415-14cf-5e8d-888d-141ae94a67d2
STIX ID: report--ce667415-14cf-5e8d-888d-141ae94a67d2
Feed Name: CosmicBytez Labs
Threat Score
A critical CVE (CVE-2026-47140, CVSS 10.0) was disclosed in the vm2 Node.js sandbox allowing sandboxed code to escape to host execution by accessing omitted builtins (`process` and `inspector/promises`). The advisory documents exploit primitives (inspector.promises Runtime.evaluate and process require paths), impact (full host RCE, environment and child-process access), and recommends upgrading to vm2 3.11.4 and using allowlist and OS-level isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
