logo

Critical sandbox escape flaw found in popular vm2 NodeJS library

ID: 9fed6ba2-9237-55c4-bb8b-e63dddec21fb

STIX ID: report--9fed6ba2-9237-55c4-bb8b-e63dddec21fb

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical sandbox-escape vulnerability (CVE-2026-22709) in the vm2 Node.js sandbox library permits attackers to bypass Promise callback sanitization and run arbitrary code on the host; an exploit snippet was published and maintainers issued fixes in versions 3.10.1–3.10.3, so users are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.