CVE-2026-22709: vm2 Sandbox Escape Vulnerability
ID: 9e0ef39b-8275-511c-8a91-f3ca0ae38f9c
STIX ID: report--9e0ef39b-8275-511c-8a91-f3ca0ae38f9c
Feed Name: SOCRadar Blog
Threat Score
CVE-2026-22709 is a critical (CVSS 9.8) sandbox-escape vulnerability in the vm2 Node.js library that allows remote, unauthenticated attackers to execute arbitrary host code by exploiting vm2's improper handling of Promises from async functions; versions up to 3.10.1 are affected and the issue is fixed in 3.10.2 — immediate remediation is to upgrade and apply additional isolation and input controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
