CVE-2026-47208
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.76%
- CWE
- CWE-913
- Published
- 2026-06-12
- Last modified
- 2026-06-13
Affected products
- patriksimek vm2
Weakness type
Related vulnerabilities
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-65181 — Apache Impala: RCE via External Data Source Class Loading
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-48105 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
- CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed...
- CVE-2026-71470 — Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa
- CVE-2026-47698 — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators