vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.
References
Configurations
No configuration.
History
12 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/patriksimek/vm2/security/advisories/GHSA-76w7-j9cq-rx2j - |
12 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 15:16
Updated : 2026-06-17 10:54
NVD link : CVE-2026-47208
Mitre link : CVE-2026-47208
CVE.ORG link : CVE-2026-47208
JSON object : View
Products Affected
No product.
CWE
CWE-913
Improper Control of Dynamically-Managed Code Resources
