Back

CRITICAL

vm2: Sandbox escape

Published May 13, 2026

Description

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM mutate shared host Object.prototype, Array.prototype, and Function.prototype from inside the sandbox This vulnerability is fixed in 3.11.0.

Affected products

Remediation

Red Hat statement

vm2 is vulnerable to sandbox escape via host prototype mutation through the VM bridge reflection handlers. A remote unauthenticated attacker who can run code in a default VM or NodeVM may modify shared host JavaScript prototypes and achieve arbitrary code execution. Fixed in vm2 3.11.0.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 13, 2026
Updated Sep 7, 2026
Reserved May 4, 2026
CISA Vulnrichment
Updated May 15, 2026
NVD
Status Modified
Modified Sep 7, 2026
Red Hat
Severity Important
Public date May 13, 2026
ENISA EUVD
Assigner GitHub_M
Published May 13, 2026
Updated Sep 7, 2026
Exploited since n/a
EUVD-2026-30075 GHSA-VWRP-X96C-MHWQ