Vulnerabilità ed exploit
I breakout dalla sandbox di vm2 si moltiplicano oltre una singola correzione vm2 sta assomigliando meno a un singolo bug e più a un confine di contenimento rotto. L’approccio di patch-for-one-CVE non funziona qui, perché la divulgazione si è ampliata in un cluster di sandbox escape attraverso release più vecchie, e qualsiasi escape raggiungibile trasforma JavaScript fornito dal tenant in esecuzione di codice a livello host all’interno dell’app Node.js.
3 fonti · 8 mag
CVE-2026-22709 NVD KEV
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 1% (69º percentile).
CVE-2026-26956 NVD KEV
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 0.8% (56º percentile).
Cronologia Fonti 8 mag Socket.dev
Socket Releases Free Certified Patches for Critical vm2 Sand...
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
originale 7 mag The Hacker News
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
12 vm2 flaws (CVSS up to 10.0) enable sandbox escape in ≤3.11.1, causing remote code execution risk; patched in 3.11.2.
originale 6 mag BleepingComputer
Critical vm2 sandbox bug lets attackers execute code on hosts
A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system.
originale Part of the PlainSec briefing for 2026-05-09
Every edition of this story: I breakout dalla sandbox di vm2 si moltiplicano oltre una singola correzione
Altro da oggi
Vulnerabilità ed exploit
I breakout dalla sandbox di vm2 si moltiplicano oltre una singola correzione vm2 sta assomigliando meno a un singolo bug e più a un confine di contenimento rotto. L’approccio di patch-for-one-CVE non funziona qui, perché la divulgazione si è ampliata in un cluster di sandbox escape attraverso release più vecchie, e qualsiasi escape raggiungibile trasforma JavaScript fornito dal tenant in esecuzione di codice a livello host all’interno dell’app Node.js.
3 fonti · 8 mag
CVE-2026-22709 NVD KEV
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 1% (69º percentile).
CVE-2026-26956 NVD KEV
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 0.8% (56º percentile).
Cronologia Fonti 8 mag Socket.dev
Socket Releases Free Certified Patches for Critical vm2 Sand...
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
originale 7 mag The Hacker News
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
12 vm2 flaws (CVSS up to 10.0) enable sandbox escape in ≤3.11.1, causing remote code execution risk; patched in 3.11.2.
originale 6 mag BleepingComputer
Critical vm2 sandbox bug lets attackers execute code on hosts
A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system.
originale Part of the PlainSec briefing for 2026-05-09
Every edition of this story: I breakout dalla sandbox di vm2 si moltiplicano oltre una singola correzione
Altro da oggi