CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)
ID: dcbffffb-5366-5dde-912e-3cbfcbe6d79b
STIX ID: report--dcbffffb-5366-5dde-912e-3cbfcbe6d79b
Feed Name: CosmicBytez Labs
Threat Score
CVE-2026-47137 is a critical (CVSS 10.0) vm2 sandbox escape where a strict equality check against false (options.require === false) can be bypassed using non-boolean falsy values (for example require:0), allowing nesting-based sandbox escapes to achieve host remote code execution; the issue is fixed in vm2 3.11.4 and users should upgrade or apply mitigations such as validating the require option and disabling nesting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
