CVE-2026-47208
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.
Ver en NVDAnálisis
La popular biblioteca vm2 para Node.js presenta una vulnerabilidad de escape de sandbox que permite a un atacante ejecutar comandos arbitrarios directamente en el sistema host. Al obtener control total sobre el entorno de ejecución, esta falla compromete la integridad de cualquier servidor o contenedor que dependa de vm2 para aislar código. Se recomienda actualizar a la versión 3.11.4 de manera inmediata.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-913EPSS
Descripción técnica
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.