HomeSecurityvm2 Node.js: 12 critical vulnerabilities allow sandbox escape

vm2 Node.js: 12 critical vulnerabilities allow sandbox escape

Twelve critical vulnerabilities have been discovered in the Node.js vm2 library . The vulnerabilities could be exploited by malicious users to escape the sandbox environment and execute arbitrary code on vulnerable systems. vm2 is a popular open source library used to safely execute untrusted JavaScript code by intercepting and proxying JavaScript objects . The library has become particularly popular in applications that need to execute user-submitted code, such as serverless functions, bots, and development tools.

See also: vm2 Node.js: “sandbox escape” vulnerability allows code execution

vm2 Node.js vulnerabilities

vm2 Node.js: All vulnerabilities identified

  • CVE-2026-24118 (CVSS Score: 9.8) – A sandbox escape vulnerability via “ lookupGetter ” could allow an attacker to execute arbitrary code on the underlying host. (Affects versions
  • CVE-2026-24120 (CVSS Score: 9.8) – A bypass patch for CVE-2023-37466, which could allow attackers to escape the sandbox via the species of promise objects and execute arbitrary commands on the underlying host. (Affects versions
  • CVE-2026-24781 (CVSS Score: 9.8) – A vulnerability, which allows sandbox escape via the “inspect” function, allows an attacker to execute arbitrary code on the underlying host. (Affects versions
  • CVE-2026-26332 (CVSS score: 9.8) – A vulnerability, which allows sandbox escape via “SuppressedError” and allows an attacker to execute arbitrary code on the underlying host. (Affects versions
  • CVE-2026-26956 (CVSS score: 9.8) – A vulnerability in the protection mechanism that allows sandbox escape with arbitrary code execution by triggering a TypeError generated by Symbol-to-string coercion. (Affects version 3.10.4, confirmed in Node.js 25.6.1, fixed in version 3.10.5)
  • CVE-2026-43997 (CVSS Score: 10.0) – A vulnerability code injection that allows an attacker to obtain the host Object and escape the sandbox, leading to arbitrary code execution. (Affects versions
  • CVE-2026-43999 (CVSS Score: 9.9) – A vulnerability that allows bypassing the NodeVM built-in allowlist and allows an attacker to load excluded builtins such as child_process and achieve remote code execution . (Affects version 3.10.5, updated to version 3.11.0)
  • CVE-2026-44005 (CVSS Score: 10.0) – A vulnerability that allows attacker-controlled JavaScript to escape the sandbox and trigger prototype pollution. (Affects versions 3.9.6-3.10.5, updated in version 3.11.0)
  • CVE-2026-44006 (CVSS Score: 10.0) – A code injection via “BaseHandler.getPrototypeOf” that allows sandbox escape and remote code execution. (Affects versions
  • CVE-2026-44007 (CVSS Score: 9.1) – An improper access control that allows sandbox escape and execution of arbitrary operating system commands on the underlying host. (Affects versions
  • CVE-2026-44008 (CVSS score: 9.8) – A sandbox escape vulnerability via “neutralizeArraySpeciesBatch()” allows an attacker to execute arbitrary commands on the underlying host. (Affects versions
  • CVE-2026-44009 (CVSS score: 9.8) – A vulnerability, which allows sandbox escape via null proto exception and allows an attacker to execute arbitrary commands on the underlying host. (Affects versions

The revelation comes a few months after the release of fixes for another critical sandbox escape vulnerability ( CVE-2026-22709 , CVSS score: 9.8 ) that could lead to arbitrary code execution on the underlying system.

See also: Node.js fixes critical vulnerabilities

vm2 Node.js: 12 critical vulnerabilities allow sandbox escape

The new vulnerabilities highlight the challenge of securely isolating untrusted code in JavaScript sandbox environments. vm2 maintainer Patrik Simekhad previously acknowledged that new exploits would likely be discovered in the future, a fact borne out by the current situation.

Practical protection tips

Experts recommend immediately upgrading to version 3.11.2 or later for optimal protection. Administrators can check installed versions and apply fixes. For immediate mitigation, it is recommended to disable vm2 where possible, apply strict whitelists, and isolate sandboxes in containers or isolated-vm environments.

To detect potential exploits, organizations should monitor for anomalous activities such as spawning of unexpected child_process instances or unusual network traffic.

See also: Escape Exploit for Chrome Sandbox sells for $1 million

In the long term, a transition to safer alternatives is recommended. Current developments highlight the need for continued vigilance in managing vulnerabilities in critical dependencies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS