Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44007

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 9.1
CVSS3: 9.9
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host. Any application that runs untrusted code inside a NodeVM with nesting: true is fully compromised. This vulnerability is fixed in 3.11.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Версия до 3.11.1 (исключая)

EPSS

Процентиль: 58%
0.0096
Низкий

9.1 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-284
CWE-1100

Связанные уязвимости

CVSS3: 9.9
redhat
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host. Any application that runs untrusted code inside a NodeVM with nesting: true is fully compromised. This vulnerability is fixed in 3.11.1.

CVSS3: 9.1
github
3 месяца назад

vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution

CVSS3: 9.1
fstec
3 месяца назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 58%
0.0096
Низкий

9.1 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-284
CWE-1100