CVE-2026-26956

CRITICAL

vm2: WASM Sandbox Escape (Node 25 only)

Title source: cna
STIX 2.1

Description

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

References (2)

Core 2
Core References

Scores

CVSS v3 9.8
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-693
Status published
Products (3)
npm/vm2 3.10.4 - 3.10.5npm
patriksimek/vm2 = 3.10.4
vm2_project/vm2 < 3.10.5
Published May 04, 2026
Tracked Since May 04, 2026