vm2: Sandbox escape
Published May 13, 2026
10.0
CRITICALCVSS 3.1
EPSS 0.83%
Description
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM mutate shared host Object.prototype, Array.prototype, and Function.prototype from inside the sandbox This vulnerability is fixed in 3.11.0.
Affected products
-
- Version >= 3.9.6, < 3.11.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Patriksimek | Vm2 | n/a |
|
- ≥ 3.9.6 · < 3.11.0
No data.
Red Hat Ansible Automation Platform 2.1
ansible-automation-platform/automation-portal:1785854226
Fixed · RHSA-2026:50850
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.1 | ansible-automation-platform/automation-portal:1785854226 | Fixed | RHSA-2026:50850 |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
vm2
npm
Introduced 3.9.6 Fixed 3.11.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | vm2 | 3.9.6 | 3.11.0 |
Remediation
Red Hat statement
vm2 is vulnerable to sandbox escape via host prototype mutation through the VM bridge reflection handlers. A remote unauthenticated attacker who can run code in a default VM or NodeVM may modify shared host JavaScript prototypes and achieve arbitrary code execution. Fixed in vm2 3.11.0.
References (10)
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/security/cve/CVE-2026-44005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477205 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30075 Advisory
- https://github.com/advisories/GHSA-vwrp-x96c-mhwq Advisory
- https://github.com/patriksimek/vm2/releases/tag/v3.11.0
- https://github.com/patriksimek/vm2/security/advisories/GHSA-vwrp-x96c-mhwq exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44005
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44005.json
- https://www.cve.org/CVERecord?id=CVE-2026-44005
Change history (0)
No recorded changes yet.