Vm2 Project Vm2 vulnerabilities
73 known vulnerabilities affecting vm2_project/vm2.
Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH13MEDIUM10
Vulnerabilities
Page 3 of 4
CVE-2026-100721P2CRITICAL≥ 0, < 3.12.22026-10-05
CVE-2026-100721 [CRITICAL] CWE-863 vm2: NodeVM custom resolution bypasses external path boundaries
vm2: NodeVM custom resolution bypasses external path boundaries
## Summary
At source revision `91034466bfb7f56b95fd48083ec6ca36d058f164` of vm2 3.11.8, an untrusted `NodeVM` guest can turn one allowlisted custom-resolved module into authorization for a separate file whose path merely shares the resolved path's string prefix. `LegacyResolver.customResolve` stores the resolved path in `this.externa
ghsa
CVE-2022-25893P3CRITICALCVSS 9.8fixed in 3.9.10≥ unspecified, < 3.9.102022-12-21
CVE-2022-25893 [CRITICAL] CWE-471 CVE-2022-25893: The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototy
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
ghsanvdosv
CVE-2026-92955P2CRITICAL≥ 0, < 3.11.82026-10-05
CVE-2026-92955 [CRITICAL] CWE-913 vm2: Sandbox Escape (NodeVM)
vm2: Sandbox Escape (NodeVM)
## Summary
It being possible to obtain the host `__proto__` getter/setter, has been used in many reports:
- https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg
- https://github.com/patriksimek/vm2/security/advisories/GHSA-grj5-jjm8-h35p
- https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-9
ghsa
CVE-2026-92948P2CRITICAL≥ 3.9.6, < 3.11.72026-10-01
CVE-2026-92948 [CRITICAL] CWE-693 vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
## Summary
On Node.js 24 and newer, `vm2` can expose the host `node:test` module to sandboxed `NodeVM` code when the embedder explicitly allows the `node:test` builtin. Sandbox code can reach that module through `require('node:node:test')` and call `run()` with attacker-controlled `execA
ghsa
CVE-2026-92957P2CRITICAL≥ 0, < 3.11.72026-10-01
CVE-2026-92957 [CRITICAL] CWE-269 vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
## Summary
NodeVM normalizes `node:`-prefixed builtin specifiers during `require()` resolution, but it does not normalize user-provided negative builtin entries in wildcard policy.
As a result, this configuration:
```js
new NodeVM({
require: {
builtin: ['*', '-node:child_process']
}
});
```
does not deny
ghsa
CVE-2026-44009P3CRITICALCVSS 9.8fixed in 3.11.22026-05-13
CVE-2026-44009 [CRITICAL] CWE-668 CVE-2026-44009: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
ghsanvd
CVE-2026-92934P3CRITICAL≥ 0, < 3.11.82026-10-05
CVE-2026-92934 [CRITICAL] CWE-693 vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
## Summary
vm2 `3.11.6` (this fork's latest release) contains an incomplete-fix bypass of the Error.cause host-reference sanitization added in GHSA-m283-3h24-438v (commit `7e3faaf`). Sandbox code that catches a host-wrapp
ghsa
CVE-2026-92953P2CRITICAL≥ 3.11.0, < 3.11.82026-10-05
CVE-2026-92953 [CRITICAL] CWE-1321 vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
## Summary
vm2's current host-intrinsic prototype protection is incomplete. The fix for `GHSA-vwrp-x96c-mhwq` blocks sandbox writes into classic host intrinsics such as `Object.prototype`, `Array.prototype`, and `Function.prototype`, but current
ghsa
CVE-2019-10761P3HIGHCVSS 8.3fixed in 3.6.11≥ unspecified, < 3.6.112022-07-13
CVE-2019-10761 [HIGH] CWE-674 CVE-2019-10761: This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from th
This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and ex
ghsanvdosv
CVE-2026-47139P3HIGH≥ 0, < 3.11.42026-05-29
CVE-2026-47139 [HIGH] CWE-693 NodeVM network builtin exclusions bypass via internal _http_client and _http_server
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
## Summary
`NodeVM` supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to `http`, `https`, `http2`, `net`, `dgram`, `tls`, `dns`, and `dns/promises` is blocked.
However, Node.js also exposes underscored internal HTTP builtins such as `
ghsa
CVE-2026-47683P3HIGH≥ 0, < 3.11.62026-08-17
CVE-2026-47683 [HIGH] CWE-770 vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
## Summary
vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The cap wraps `Buffer.alloc`, `Buffer.allocUnsafe`,
ghsa
CVE-2026-92947P3CRITICAL≥ 0, < 3.11.72026-10-05
CVE-2026-92947 [CRITICAL] CWE-200 vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
### Summary
Sandboxed code is able to disclose host memory used by small allocations by `Buffer.from`, `Buffer.concat`.
### Details
vm2 exposes `Buffer` object to sandboxed code by default. Small [`Buffer` allocations](https://nodejs.org/api/buffer.html#static-method-bufferallocunsafesize)
ghsa
CVE-2026-44001P3HIGHCVSS 8.6fixed in 3.11.02026-05-13
CVE-2026-44001 [HIGH] CVE-2026-44001: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2) only sanitized the onRejected callback in .then() and .catch
ghsanvd
CVE-2026-47135P3HIGH≥ 0, < 3.11.42026-05-29
CVE-2026-47135 [HIGH] CWE-693 vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
## Summary
vm2 3.11.2 `Symbol.for` override in `setup-sandbox.js` only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's `set`/`defineProperty`/`deleteProperty` traps having **no** `isDangerousCrossRealmSymbol` key c
ghsa
CVE-2026-44004P3HIGHCVSS 7.5fixed in 3.11.02026-05-13
CVE-2026-44004 [HIGH] CWE-770 CVE-2026-44004: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc(
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaust host memory and crash the process with a FATAL ERROR: Re
ghsanvd
CVE-2026-47209P3HIGH≥ 0, < 3.11.42026-05-29
CVE-2026-47209 [HIGH] CWE-693 vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
## Summary
The `BaseHandler.set` trap in `bridge.js` (line 1231) ignores the `receiver` parameter and unconditionally writes to the host target object. Per the Proxy `set` trap specification, when `receiver !== proxy` (e.g., when a chil
ghsa
CVE-2026-92958P3HIGH≥ 0, < 3.11.72026-10-01
CVE-2026-92958 [HIGH] CWE-269 vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
## Summary
NodeVM's builtin wildcard policy can allow sandboxed code to access `fs/promises` even when the embedder denies `fs`.
With the following configuration:
```js
require: {
builtin: ['*', '-fs', '-child_process']
}
```
`require('fs')` and `require('child_process')
ghsa
CVE-2026-92954P3CRITICAL≥ 3.10.0, < 3.11.82026-10-05
CVE-2026-92954 [CRITICAL] CWE-248 vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
## Summary
vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) can still be used to terminate the host Node.js process when sandbox code calls a host-realm function that returns a rejected host Promise and
ghsa
CVE-2026-92942P3CRITICALCVSS 10.0≥ 0, < 3.11.72026-10-05
CVE-2026-92942 [CRITICAL] CWE-400 vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)
vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)
### Vulnerability Summary
vm2's `VM({ timeout })` option is documented and relied upon as the mechanism that bounds how long sandboxed code may execute. In the current implementation, the timeout only wraps the single synchronous call to `VM#run()` (via `doW
ghsa
CVE-2026-100723P3MEDIUM≥ 0, < 3.12.22026-10-05
CVE-2026-100723 [MEDIUM] CWE-200 vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
## Summary
When an application explicitly exposes Node's `zlib` module through vm2's `NodeVM` builtin allowlist, an untrusted guest can obtain a pool-backed host `Buffer` from `zlib.deflateSync`, create a full-width view of its backing `ArrayBuffer`, read bytes outside the compressed result, and flip a byte in an un
ghsa