Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-47208

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

EPSS

Процентиль: 52%
0.00762
Низкий

10 Critical

CVSS3

Дефекты

CWE-913

Связанные уязвимости

CVSS3: 6.6
redhat
около 2 месяцев назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

CVSS3: 10
github
2 месяца назад

vm2 is Vulnerable to Sandbox Breakout Through Promise Species

EPSS

Процентиль: 52%
0.00762
Низкий

10 Critical

CVSS3

Дефекты

CWE-913