Patriksimek Vm2 vulnerabilities
74 known vulnerabilities affecting patriksimek/vm2.
Total CVEs
74
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL47HIGH15MEDIUM11LOW1
Vulnerabilities
Page 2 of 4
CVE-2026-92960P2CRITICALCVSS 10.0fixed in 3.11.62026-09-17
CVE-2026-92960 [CRITICAL] CWE-200 CVE-2026-92960: vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configura
vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolv
nvd
CVE-2026-47210P2CRITICALCVSS 9.8fixed in 3.11.42026-06-12
CVE-2026-47210 [CRITICAL] CWE-913 CVE-2026-47210: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerabilit
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). In the tested configuration, a JSPI-backed Promis
nvd
CVE-2026-26332P2CRITICALCVSS 10.0fixed in 3.11.02026-05-04
CVE-2026-26332 [CRITICAL] CWE-94 CVE-2026-26332: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attack
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
nvd
CVE-2026-24118P2CRITICALCVSS 9.8fixed in 3.11.02026-05-04
CVE-2026-24118 [CRITICAL] CWE-94 CVE-2026-24118: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox br
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.
nvd
CVE-2026-45411P2CRITICALCVSS 9.8fixed in 3.11.32026-05-13
CVE-2026-45411 [CRITICAL] CWE-668 CVE-2026-45411: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host except
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the
nvd
CVE-2026-92935P2CRITICALCVSS 9.0≥ 3.11.4, < 3.11.72026-09-17
CVE-2026-92935 [CRITICAL] CWE-913 CVE-2026-92935: vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`) satisfies the guard that is meant to reject nesting without an explicit requi
nvd
CVE-2026-92956P2CRITICALCVSS 10.0≥ 3.10.1, < 3.11.72026-09-17
CVE-2026-92956 [CRITICAL] CWE-693 CVE-2026-92956: vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sand
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox
nvd
CVE-2026-26956P2CRITICALCVSS 9.8v= 3.10.42026-05-04
CVE-2026-26956 [CRITICAL] CWE-693 CVE-2026-26956: vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox e
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
nvd
CVE-2026-44008P2CRITICALCVSS 9.8fixed in 3.11.22026-05-13
CVE-2026-44008 [CRITICAL] CWE-668 CVE-2026-44008: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpecies
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object. This allows attack
nvd
CVE-2026-92944P2CRITICALCVSS 9.8≥ 3.10.2, < 3.11.72026-09-17
CVE-2026-92944 [CRITICAL] CWE-693 CVE-2026-92944: vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promis
vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that returns a Promise with an attacker-controlled constructor Symbol.speci
nvd
CVE-2026-43998P2HIGHCVSS 8.5v3.10.52026-05-13
CVE-2026-43998 [HIGH] CWE-59 CVE-2026-43998: vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can
vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not dereference symlinks) but module loading uses Node's native
nvd
CVE-2026-47686P2CRITICALCVSS 9.9fixed in 3.11.62026-08-17
CVE-2026-47686 [CRITICAL] CWE-693 CVE-2026-47686: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws
nvd
CVE-2026-92941P2CRITICALCVSS 10.0≥ 3.11.3, < 3.11.72026-09-17
CVE-2026-92941 [CRITICAL] CWE-732 CVE-2026-92941: vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing a
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling
nvd
CVE-2026-92951P2CRITICALCVSS 9.9fixed in 3.11.72026-09-17
CVE-2026-92951 [CRITICAL] CWE-706 CVE-2026-92951: vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlis
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute
nvd
CVE-2026-47131P2CRITICALCVSS 10.0fixed in 3.11.42026-06-12
CVE-2026-47131 [CRITICAL] CWE-913 CVE-2026-47131: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, which allows the escape from the sandbox. This allows
nvd
CVE-2026-47698P2CRITICALCVSS 9.8fixed in 3.11.62026-08-17
CVE-2026-47698 [CRITICAL] CWE-913 CVE-2026-47698: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.j
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host
nvd
CVE-2026-100721P2CRITICALCVSS 9.0fixed in 3.12.22026-09-27
CVE-2026-100721 [CRITICAL] CWE-863 CVE-2026-100721: vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an e
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath
nvd
CVE-2026-44006P3CRITICALCVSS 10.0fixed in 3.11.02026-05-13
CVE-2026-44006 [CRITICAL] CWE-94 CVE-2026-44006: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.g
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
nvd
CVE-2026-92955P2CRITICALCVSS 10.0fixed in 3.11.82026-09-17
CVE-2026-92955 [CRITICAL] CWE-913 CVE-2026-92955: vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access
vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.
nvd
CVE-2026-92948P2CRITICALCVSS 9.9≥ 3.9.6, < 3.11.72026-09-17
CVE-2026-92948 [CRITICAL] CWE-693 CVE-2026-92948: vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a
vm2 versions >= 3.9.6 and therefore executes arbitrary JavaScript in an unrestricted host Node process outside the NodeVM sandbox. Fixed in vm2 3.11.7.
nvd