CVE-2026-26956: exploitation status and patch state

CVE-2026-26956 · CVSS 9.8 CRITICAL · EPSS 1%

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

Is CVE-2026-26956 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-26956

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.