Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24120

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 9.1

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.

A flaw was found in vm2, an open-source sandbox for Node.js. This vulnerability allows a remote attacker to bypass existing security controls, specifically the fix for CVE-2023-37466. By circumventing the sandbox, an attacker can execute arbitrary commands on the host system, leading to a complete compromise of the affected system.

Отчет

This Important flaw in vm2 allows for arbitrary code execution through a sandbox escape. Red Hat products are not affected by this vulnerability, as the component is either not present or the vulnerable code cannot be controlled by an adversary in Red Hat's supported configurations. Red Hat Developer Hub is not affected by this vulnerability as the vm2 package is a development dependency and the code could not be reached by an adversary. The Ansible Portal product already ships the vm2 v3.10.5 which already contains the fix.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2466529vm2: vm2: Arbitrary code execution due to sandbox escape vulnerability

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.

CVSS3: 9.8
github
3 месяца назад

VM2 Has Sandbox Breakout Through Promise Species

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость функции resetPromiseSpecies() библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю обойти защитный механизм песочницы и выполнить произвольные команды

9.1 Critical

CVSS3