CVE-2026-22709
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 1% (69º percentile).
Vulnerabilità · 145 giorni fa
vm2 sta assomigliando meno a un singolo bug e più a un confine di contenimento rotto. L’approccio di patch-for-one-CVE non funziona qui, perché la divulgazione si è ampliata in un cluster di sandbox escape attraverso release più vecchie, e qualsiasi escape raggiungibile trasforma JavaScript fornito dal tenant in esecuzione di codice a livello host all’interno dell’app Node.js.
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 1% (69º percentile).
CVSS 9.8 CRITICAL: vm2 is an open source vm/sandbox for Node.js. EPSS 0.8% (56º percentile).
3 fonti che coprono questa storia
Socket Releases Free Certified Patches for Critical vm2 Sand...
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
12 vm2 flaws (CVSS up to 10.0) enable sandbox escape in ≤3.11.1, causing remote code execution risk; patched in 3.11.2.
Critical vm2 sandbox bug lets attackers execute code on hosts
A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system.
Part of the PlainSec briefing for 2026-05-09