#vm2
All CosmicBytez Labs articles tagged #vm2, across news, security advisories, how-to guides, and projects.
- Security
vm2 NodeVM External-Module Resolver Authorization Bypass (CVE-2026-100721)
vm2 before 3.12.2 lets sandboxed guest code escape via a prefix-match flaw in the NodeVM external-module resolver, enabling host code execution.
- Security
vm2 Sandbox Escape via Error.cause Host Object Leak (CVE-2026-47686)
Critical vm2 sandbox escape allows Node.js sandbox code to access the host process object via unsanitized Error.cause, enabling full RCE.
- Security
vm2 Prototype Chain Escape via Function.prototype.call Stacking (CVE-2026-47698)
Critical vm2 flaw lets sandboxed code sever host intrinsic prototype chains using stacked Function.prototype.call, escaping the sandbox entirely.
- Security
CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)
A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows sandboxed code to obtain the host TypeError constructor via Buffer.__lookupGetter__ abuse,...
- Security
CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)
A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows attackers to bypass the require: false security option using falsy values, circumventing the...
- Security
CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)
A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows sandboxed code to access the host process via the process and inspector/promises builtins,...
- Security
CVE-2026-47208: vm2 General Sandbox Breakout — Arbitrary Host Execution (CVSS 10.0)
A CVSS 10.0 critical vulnerability in vm2 for Node.js allows sandbox code to escape and execute arbitrary OS commands on the host system. Patched in vm2 3.11.4.