logo

CVE-2026-22709: vm2 Sandbox Escape Vulnerability

ID: 9e0ef39b-8275-511c-8a91-f3ca0ae38f9c

STIX ID: report--9e0ef39b-8275-511c-8a91-f3ca0ae38f9c

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-01-29

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2026-22709 is a critical (CVSS 9.8) sandbox-escape vulnerability in the vm2 Node.js library that allows remote, unauthenticated attackers to execute arbitrary host code by exploiting vm2's improper handling of Promises from async functions; versions up to 3.10.1 are affected and the issue is fixed in 3.10.2 — immediate remediation is to upgrade and apply additional isolation and input controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.