Vm2 Project Vm2 vulnerabilities
73 known vulnerabilities affecting vm2_project/vm2.
Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH13MEDIUM10
Vulnerabilities
Page 2 of 4
CVE-2026-92939P2CRITICAL≥ 3.11.3, < 3.11.72026-10-01
CVE-2026-92939 [CRITICAL] CWE-114 vm2 crypto builtin loads attacker native code through setEngine
vm2 crypto builtin loads attacker native code through setEngine
Summary
vm2 3.11.6 exposes the host `crypto` module to a `NodeVM` when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. `crypto.setEngine()` accepts a filesystem path and asks OpenSSL to dynamically load the referenced native library.
An a
ghsa
CVE-2026-43998P2HIGHCVSS 8.5v3.10.52026-05-13
CVE-2026-43998 [HIGH] CWE-59 CVE-2026-43998: vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can
vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not dereference symlinks) but module loading uses Node's native
ghsanvd
CVE-2026-24120P2CRITICALCVSS 9.8fixed in 3.10.52026-05-04
CVE-2026-24120 [CRITICAL] CVE-2026-24120: vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.
ghsanvd
CVE-2026-47140P2CRITICAL≥ 0, < 3.11.42026-05-29
CVE-2026-47140 [CRITICAL] CWE-693 NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
## Summary
`NodeVM` blocks several dangerous Node.js builtins such as `module`, `worker_threads`, `cluster`, `vm`, `repl`, and `inspector`.
However, the denylist misses `process` and `inspector/promises`. Both can be used from sandboxed code to reach host-side execution primit
ghsa
CVE-2026-47210P2CRITICAL≥ 0, < 3.11.42026-05-29
CVE-2026-47210 [CRITICAL] CWE-913 vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
### Summary
A sandbox escape vulnerability in `vm2` allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (`WebAssembly.promising` / `WebAssembly.Suspending`). In the tested configuration, a JSPI-backed Promise can reach `Promise.protot
ghsa
CVE-2021-23449P2CRITICALCVSS 10.0fixed in 3.9.4≥ unspecified, < 3.9.42021-10-18
CVE-2021-23449 [CRITICAL] CWE-1321 CVE-2021-23449: This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
ghsanvdosv
CVE-2026-47137P2CRITICALCVSS 10.0≥ 0, < 3.11.42026-05-29
CVE-2026-47137 [CRITICAL] CWE-913 vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
## Summary
The fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in `nodevm.js` line 263 that blocks the combination `nesting: true` + `require: false`. However, the check uses strict equality (`options.require === false`), which is trivially bypassed
ghsa
CVE-2026-44006P3CRITICALCVSS 10.0fixed in 3.11.02026-05-13
CVE-2026-44006 [CRITICAL] CWE-94 CVE-2026-44006: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.g
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
ghsanvd
CVE-2026-92935P2CRITICAL≥ 3.11.4, < 3.11.72026-10-01
CVE-2026-92935 [CRITICAL] CWE-913 vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
## Summary
The `NodeVM` constructor computes `hasRealRequireConfig` using `typeof requireOpts === 'object' && requireOpts !== null`, so `require: []` bypasses the guard intended to reject `nesting` without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the array to undefi
ghsa
CVE-2026-44007P3CRITICALCVSS 9.1fixed in 3.11.12026-05-13
CVE-2026-44007 [CRITICAL] CWE-284 CVE-2026-44007: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and execu
ghsanvd
CVE-2026-44005P3CRITICALCVSS 10.0≥ 3.9.6, < 3.11.02026-05-13
CVE-2026-44005 [CRITICAL] CWE-94 CVE-2026-44005: vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable pro
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited No
ghsanvd
CVE-2026-92944P2CRITICAL≥ 3.10.2, < 3.11.72026-10-01
CVE-2026-92944 [CRITICAL] CWE-693 vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
## Reporter
- Name or handle: `[YMsora]`
- Report date: 2026-08-14
## Summary
The latest published vm2 release, **3.11.5**, and the current `main` branch are vulnerable to a sandbox escape when used on Node.js 26. An ordinary fulfilled Promise created by an async function can retain an attacker-co
ghsa
CVE-2026-92956P2CRITICAL≥ 3.10.1, < 3.11.72026-10-05
CVE-2026-92956 [CRITICAL] CWE-693 vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
## Summary
There is a sandbox escape in vm2 `3.11.5` / current HEAD when it is used on Node.js 26. The issue is reachable from a default `new VM()` sandbox. No `NodeVM`, `require` permission, host object injection, or intentionally unsafe configuration is required.
The escape is a patch-bypass of the same securi
ghsa
CVE-2021-23555P3CRITICALCVSS 9.8fixed in 3.9.6≥ unspecified, < 3.9.62022-02-11
CVE-2021-23555 [CRITICAL] CVE-2021-23555: The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error object
The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.
ghsanvdosv
CVE-2026-43997P3CRITICALCVSS 10.0fixed in 3.11.02026-05-13
CVE-2026-43997 [CRITICAL] CWE-94 CVE-2026-43997: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Obj
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.
ghsanvd
CVE-2026-47686P2CRITICAL≥ 0, < 3.11.62026-08-17
CVE-2026-47686 [CRITICAL] CWE-693 VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
**Affected:** vm2 {
throw new Error('fail', { cause: process });
}
}
});
const result = vm.run(`
try {
hostFn();
} catch (e) {
// .cause is not sanitized, so we get a direct reference to host process
const proc = e.cause;
proc.mainModule.require('child_process').execSync('id').toString();
}
`);
console.log(res
ghsa
CVE-2026-92951P2CRITICAL≥ 0, < 3.11.72026-10-01
CVE-2026-92951 [CRITICAL] CWE-706 vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
### Summary
vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages.
When `NodeVM` enables an `external` allowlist together with a custom `
ghsa
CVE-2026-92941P2CRITICAL≥ 3.11.3, < 3.11.72026-10-01
CVE-2026-92941 [CRITICAL] CWE-732 vm2 NodeVM can replace the host process TLS trust store
vm2 NodeVM can replace the host process TLS trust store
Summary
vm2 3.11.6 exposes the host `tls` module to a `NodeVM` when that builtin is explicitly allowed. Although the module object is wrapped as read-only, its functions still execute against process-wide host state. On Node.js versions that provide `tls.setDefaultCACertificates()`, sandbox code can replace the certificate authorities trusted by subs
ghsa
CVE-2026-47698P2CRITICAL≥ 0, < 3.11.62026-08-17
CVE-2026-47698 [CRITICAL] CWE-913 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
### Summary
VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.
### Details
The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insufficient and can be bypassed by replacing `indirectc
ghsa
CVE-2026-47131P2CRITICAL≥ 0, < 3.11.42026-05-29
CVE-2026-47131 [CRITICAL] CWE-913 vm2 has a Sandbox Escape issue
vm2 has a Sandbox Escape issue
### Summary
By combining `Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__")`, `Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__")`, and Node.js's `ERR_INVALID_ARG_TYPE` Error, the host's `TypeError` constructor can be obtained, which allows the escape from the sandbox.
This allows attackers to run arbitrary code.
### PoC
```js
"use strict";
const { VM } = require("vm2");
const vm =
ghsa