logo

Critical vm2 sandbox bug lets attackers execute code on hosts

ID: 9cbc2405-b6ea-5309-bc6c-00e0a44385d9

STIX ID: report--9cbc2405-b6ea-5309-bc6c-00e0a44385d9

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2026-26956) in the widely used vm2 Node.js sandbox library can be abused to escape the sandbox and execute arbitrary code on the host; a proof-of-concept is published. The issue is confirmed on vm2 3.10.4 when running on Node.js 25 with WebAssembly exception handling and JSTag enabled; maintainers recommend upgrading to 3.10.5 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.