Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47208

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. This vulnerability allows an attacker to escape the sandbox environment by writing malicious code. Successful exploitation can lead to arbitrary code execution on the host system, compromising the integrity and confidentiality of the system.

Отчет

Exploitation requires an attacker to supply untrusted malicious code to the vm2 sandbox, which is easily achieved since the component's main purpose is to execute untrusted code. Escaping the sandbox completely bypasses the intended security boundaries, leading directly to arbitrary code execution on the host system and a full compromise of confidentiality and integrity

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Red Hat Developer Hub 1.10rhdh/rhdh-hub-rhel9FixedRHSA-2026:3675408.07.2026
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:3357430.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2488382vm2: vm2: Sandbox Breakout Using Promise Species

EPSS

Процентиль: 52%
0.00762
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
около 2 месяцев назад

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

CVSS3: 10
github
2 месяца назад

vm2 is Vulnerable to Sandbox Breakout Through Promise Species

EPSS

Процентиль: 52%
0.00762
Низкий

6.6 Medium

CVSS3