cbcvebase.

Patriksimek Vm2 vulnerabilities

74 known vulnerabilities affecting patriksimek/vm2.

Total CVEs
74
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL47HIGH15MEDIUM11LOW1

Vulnerabilities

Page 3 of 4
CVE-2026-92957P2CRITICALCVSS 9.9fixed in 3.11.72026-09-17
CVE-2026-92957 [CRITICAL] CWE-269 CVE-2026-92957: vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-suppl vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy
nvd
CVE-2026-44007P3CRITICALCVSS 9.1fixed in 3.11.12026-05-13
CVE-2026-44007 [CRITICAL] CWE-284 CVE-2026-44007: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and execu
nvd
CVE-2026-44005P3CRITICALCVSS 10.0v>= 3.9.6, < 3.11.02026-05-13
CVE-2026-44005 [CRITICAL] CWE-94 CVE-2026-44005: vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable pro vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited No
nvd
CVE-2026-92953P2CRITICALCVSS 10.0≥ 3.11.0, < 3.11.82026-09-17
CVE-2026-92953 [CRITICAL] CWE-913 CVE-2026-92953: vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes fr vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after V
nvd
CVE-2026-92934P3CRITICALCVSS 9.0fixed in 3.11.82026-09-17
CVE-2026-92934 [CRITICAL] CWE-693 CVE-2026-92934: vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling ful
nvd
CVE-2026-43997P3CRITICALCVSS 10.0fixed in 3.11.02026-05-13
CVE-2026-43997 [CRITICAL] CWE-94 CVE-2026-43997: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Obj vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.
nvd
CVE-2026-47139P3HIGHCVSS 8.6fixed in 3.11.42026-06-12
CVE-2026-47139 [HIGH] CWE-693 CVE-2026-47139: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding pub vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client
nvd
CVE-2026-44009P3CRITICALCVSS 9.8fixed in 3.11.22026-05-13
CVE-2026-44009 [CRITICAL] CWE-668 CVE-2026-44009: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11. vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
nvd
CVE-2026-47683P3HIGHCVSS 8.7fixed in 3.11.62026-08-17
CVE-2026-47683 [HIGH] CWE-770 CVE-2026-47683: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in l vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can
nvd
CVE-2026-92947P3CRITICALCVSS 10.0fixed in 3.11.72026-09-17
CVE-2026-92947 [CRITICAL] CWE-200 CVE-2026-92947: vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host m vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
nvd
CVE-2026-47135P3HIGHCVSS 8.7fixed in 3.11.42026-06-12
CVE-2026-47135 [HIGH] CWE-693 CVE-2026-47135: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup- vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to
nvd
CVE-2026-47209P3HIGHCVSS 8.6fixed in 3.11.42026-06-12
CVE-2026-47209 [HIGH] CWE-693 CVE-2026-47209: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in b vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inherits from the proxy via Object.create), the property a
nvd
CVE-2026-92958P3HIGHCVSS 8.5fixed in 3.11.72026-09-17
CVE-2026-92958 [HIGH] CWE-269 CVE-2026-92958: vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the b vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpath
nvd
CVE-2026-92954P3HIGHCVSS 8.6≥ 3.10.0, < 3.11.82026-09-17
CVE-2026-92954 [HIGH] CWE-248 CVE-2026-92954: vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wrapped with a rejection-swallowing handler (lib/setup-sandbox.js), and the bridge only installs
nvd
CVE-2026-92961P3HIGHCVSS 7.5fixed in 3.11.62026-09-17
CVE-2026-92961 [HIGH] CWE-770 CVE-2026-92961: vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArra vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 intrinsics to exhaust host process memory and trigger out-of-memory conditions.
nvd
CVE-2026-44004P3HIGHCVSS 7.5fixed in 3.11.02026-05-13
CVE-2026-44004 [HIGH] CWE-770 CVE-2026-44004: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc( vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaust host memory and crash the process with a FATAL ERROR: Re
nvd
CVE-2026-100723P3HIGHCVSS 7.5fixed in 3.12.22026-09-27
CVE-2026-100723 [HIGH] CWE-200 CVE-2026-100723: vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by N
nvd
CVE-2026-92950P3HIGHCVSS 8.6fixed in 3.11.72026-09-17
CVE-2026-92950 [HIGH] CWE-453 CVE-2026-92950: vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to e vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child
nvd
CVE-2026-93604P3HIGHCVSS 7.2fixed in 3.12.12026-09-18
CVE-2026-93604 [HIGH] CWE-284 CVE-2026-93604: vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embed vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in lib/builtin.js) replaces crypto.setEngine but leaves crypto.setFips callable, and the readonly wrapper used to expose
nvd
CVE-2026-92942P3HIGHCVSS 7.5fixed in 3.11.72026-09-17
CVE-2026-92942 [HIGH] CWE-400 CVE-2026-92942: vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened global
nvd
Patriksimek Vm2 vulnerabilities | cvebase