A critical sandbox escape vulnerability in the popular Node.js vm2 library could allow attackers to execute arbitrary code on the underlying operating system. The vulnerability, tracked as CVE-2026-22709, has a CVSS score of 9.8/10.0.

“In vm2 version 3.10.0, the callback sanitization of Promise.prototype.then and Promise.prototype.catch can be bypassed,” said vm2 maintainer Patrik Simek. “This allows attackers to escape the sandbox and execute arbitrary code.”
See also: Two serious vulnerabilities in n8n allow RCE
vm2 Node.js
vm2 is a Node.js library used to execute untrusted code within a secure sandbox environment, and helps prevent the code from accessing the host environment.
The new bug stems from improper sanitization of Promise handlers , creating an escape point that leads to the execution of arbitrary code outside the sandbox.
“Async functions in JavaScript return `globalPromise` objects, not `localPromise` objects. This is because `globalPromise.prototype.then` and `globalPromise.prototype.catch` are not properly sanitized (unlike `localPromise`),” Endor LabsPeyton Kennedy and Cris Staicu wrote.

CVE-2026-22709 has been addressed in vm2 version 3.10.2. It is the latest of a series of sandbox escape vulnerabilities that have hit the library in recent years. Previous ones include: CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.
See also: WinRAR: Vulnerability allows full control of Windows systems
The discovery of CVE-2023-37903 in July 2023 also led Simek to announce that the project was being discontinued. However, these references have been removed from the latest README file available on the GitHub repository. The Security page has also been updated as of October 2025 to state that vm2 3.x versions are actively maintained.
However, the maintainer of the Node.js vm2 library warns that new workarounds will likely be discovered in the future, urging users to keep the library updated and consider other robust alternatives, such as isolated-vm.

“Instead of relying on the problematic vm model, the successor to vm2, isolated-vm, relies on V8's native Isolate interface, which offers a more stable foundation, but even then, the vm2 maintainers emphasize the importance of isolation and actually recommend Docker with logical separation between components,” Semgrep reported.
See also: Fortinet fixes FortiOS SSO bug
Due to the severity of the bug, users are advised to update to the latest version (3.10.3), which also includes fixes for other sandbox escapes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
