CVE-2026-47698
published 2026-08-17CVE-2026-47698: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
51.9th percentile
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.6 | 3.11.6 |
| vm2_project | vm2 | >= 0 < 3.11.6 | 3.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
patriksimek vm2 up to 3.11.5 Sandbox lib/bridge.js Function.prototype.call privileges management (WID-SEC-2026-2865)
vuldb·2026-08-17·CVSS 9.8
CVE-2026-47698 [CRITICAL] patriksimek vm2 up to 3.11.5 Sandbox lib/bridge.js Function.prototype.call privileges management (WID-SEC-2026-2865)
A vulnerability was found in patriksimek vm2 up to 3.11.5 and classified as critical. This impacts the function Function.prototype.call of the file lib/bridge.js of the component Sandbox. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-47698. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
ghsa·2026-08-17
CVE-2026-47698 [CRITICAL] CWE-913 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
### Summary
VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.
### Details
The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insufficient and can be bypassed by replacing `indirectcall.call(dangerousmutator, ...)` with `indirectcall.call(indirectcall, dangerousmutator, ...)` since indirect calls are not seen as dangerous.
### PoC
```js
const {VM} = require(".");
const vm = new VM();
console.log(vm.run(`
const getProto = Buffer.call.call(Buffer.call, {}.__lookupGetter__, Buffer, "__proto__");
const setProto = Buffer.call.call(Buffer.call, {}.__lookupSetter__, Buffer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-17
Published