Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26956

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

A flaw was found in vm2, an open-source sandbox for Node.js. An attacker can exploit this vulnerability by running malicious code within the VM.run() function, allowing them to escape the sandbox and gain access to the host process. This can lead to arbitrary code execution on the host system, enabling the attacker to run host commands without any host cooperation.

Отчет

This is an Important flaw in vm2, an open-source Node.js sandbox, that allows for arbitrary code execution due to a sandbox escape. An attacker can run malicious code within the VM.run() function to gain access to the host process and execute commands without host cooperation. Red Hat Developer Hub product is not affected by this vulnerability, as the affected vm2 package is used only as a development dependency and should not be reachable by the user in the final product image. For Red Hat Ansible Portal, this component is already shipping the version 3.10.5 of vm2 which contains the fix for this vulnerability, thus it's not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processorNot affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2466548vm2: Node.js: vm2: Arbitrary code execution via sandbox escape

EPSS

Процентиль: 56%
0.00921
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

CVSS3: 9.8
github
3 месяца назад

VM2 Has a WASM Sandbox Escape

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость функции VM.run() библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 56%
0.00921
Низкий

9.8 Critical

CVSS3