Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44009

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

A flaw was found in vm2 (before 3.11.2). A sandbox escape vulnerability allows remote attackers to execute arbitrary code on the host system by breaking vm2 isolation. Fixed in 3.11.2.

Отчет

vm2 is vulnerable to sandbox escape leading to arbitrary code execution on the host. A remote unauthenticated attacker who can submit code to the vm2 sandbox may escape isolation and execute arbitrary commands. Fixed in vm2 3.11.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Ansible Automation Platform 2.1ansible-automation-platform/automation-portalFixedRHSA-2026:5085005.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2477185vm2: vm2: Arbitrary Code Execution via Sandbox Escape

EPSS

Процентиль: 54%
0.00812
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

CVSS3: 9.8
github
3 месяца назад

vm2 has Sandbox Breakout Through Null Proto Exception

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 54%
0.00812
Низкий

9.8 Critical

CVSS3