Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24781

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. This vulnerability allows an attacker to escape the sandbox environment by exploiting the inspect function. Successful exploitation can lead to arbitrary code execution on the host system, compromising the integrity and confidentiality of the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processorWill not fix
Red Hat Developer Hub 1.10rhdh/rhdh-hub-rhel9FixedRHSA-2026:3675408.07.2026
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:2623416.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2466531vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function

EPSS

Процентиль: 65%
0.01186
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

CVSS3: 9.8
github
3 месяца назад

VM2 Has Sandbox Breakout Through Inspect Function

EPSS

Процентиль: 65%
0.01186
Низкий

8.1 High

CVSS3