Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26332

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.

A flaw was found in vm2, an open-source sandbox for Node.js. This vulnerability allows a remote attacker to escape the sandbox environment by exploiting the SuppressedError mechanism. Successful exploitation can lead to arbitrary code execution on the host system, compromising the integrity and confidentiality of the affected system.

Отчет

This is an Important flaw in the vm2 Node.js sandbox, enabling a remote attacker to escape the sandbox and achieve arbitrary code execution. This happens because the sandbox fails to run rejection call backs within the sandbox isolation, an attacker that have privileges or tricks the user to run a maliciously crafted code can leverage that to cause suppressed errors to be handled in the host side instead of in the local side leading to the sandbox escape. Red Hat Developer Hub is not affected by this vulnerability as the vm2 package is a development dependency and the code could not be reached by an adversary.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2466508vm2: vm2: Arbitrary code execution via SuppressedError sandbox escape

EPSS

Процентиль: 50%
0.0071
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.

CVSS3: 9.8
github
3 месяца назад

VM2 Has a Sandbox Escape Issue via SuppressedError

CVSS3: 10
fstec
3 месяца назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.0071
Низкий

9.1 Critical

CVSS3