logo

CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)

ID: ce667415-14cf-5e8d-888d-141ae94a67d2

STIX ID: report--ce667415-14cf-5e8d-888d-141ae94a67d2

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

A critical CVE (CVE-2026-47140, CVSS 10.0) was disclosed in the vm2 Node.js sandbox allowing sandboxed code to escape to host execution by accessing omitted builtins (`process` and `inspector/promises`). The advisory documents exploit primitives (inspector.promises Runtime.evaluate and process require paths), impact (full host RCE, environment and child-process access), and recommends upgrading to vm2 3.11.4 and using allowlist and OS-level isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.