logo

vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

ID: 3d70e5d1-7fb3-5b19-b258-ecccfbe5a2ff

STIX ID: report--3d70e5d1-7fb3-5b19-b258-ecccfbe5a2ff

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

Multiple critical sandbox-escape vulnerabilities (several CVEs with CVSS scores from 9.1 to 10.0) were disclosed in the vm2 Node.js library, allowing untrusted JavaScript to break out of the sandbox and execute arbitrary code on the host; affected versions are enumerated and users are advised to update to vm2 3.11.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.