logo

CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)

ID: dcbffffb-5366-5dde-912e-3cbfcbe6d79b

STIX ID: report--dcbffffb-5366-5dde-912e-3cbfcbe6d79b

Feed Name: CosmicBytez Labs

Threat Score
95/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

CVE-2026-47137 is a critical (CVSS 10.0) vm2 sandbox escape where a strict equality check against false (options.require === false) can be bypassed using non-boolean falsy values (for example require:0), allowing nesting-based sandbox escapes to achieve host remote code execution; the issue is fixed in vm2 3.11.4 and users should upgrade or apply mitigations such as validating the require option and disabling nesting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.