Critical vm2 sandbox bug lets attackers execute code on hosts
ID: 9cbc2405-b6ea-5309-bc6c-00e0a44385d9
STIX ID: report--9cbc2405-b6ea-5309-bc6c-00e0a44385d9
Feed Name: Bleeping Computer
Threat Score
A critical vulnerability (CVE-2026-26956) in the widely used vm2 Node.js sandbox library can be abused to escape the sandbox and execute arbitrary code on the host; a proof-of-concept is published. The issue is confirmed on vm2 3.10.4 when running on Node.js 25 with WebAssembly exception handling and JSTag enabled; maintainers recommend upgrading to 3.10.5 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
