CVE-2022-36067Patch(vm2_project / vm2)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
vm2

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-05-06: 1PoC Mentioned / Linked · 2026-01-28: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-05-06: 101-2801-3005-06
Signal classification1 categories
Patch
3100.0%
Full discourse3 posts
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    The post informs that CVE-2026-22709 is fixed in vm2 3.10.2 and highlights a series of sandbox escape issues affecting the library.

    10000133
    481 followersView on X
  • SecureChap@SecureChap
    Patch

    vm2 3.10.4 processed untrusted JavaScript on thousands of servers last week. This Node.js sandbox library pulls 1.3M+ weekly npm downloads. It's embedded in online coding platforms, automation pipelines, and SaaS apps designed to isolate code execution. CVE-2026-26956 was disclosed on May 6, 2026. It affects versions 3.10.4 and earlier. The fix landed in 3.10.5, with the latest release at 3.11.2. The vulnerability triggers on Node.js 25 when WebAssembly exception handling and JSTag are enabled - confirmed on v25.6.1. An attacker crafts a TypeError through Symbol-to-string conversion. This generates a host-side error object that leaks into the sandbox without sanitization. The error's constructor chain exposes Node.js internals, including the process object. From there, the attacker accesses require and child_process modules to execute arbitrary commands on the host. This marks the fourth critical sandbox escape in vm2: CVE-2026-22709 in January 2026, plus CVE-2023-30547, CVE-2023-29017, and CVE-2022-36067. vm2 maintainers have stated the library is no longer viable as a true sandbox. They recommend isolated-vm or Node's built-in permission model instead. A tool built for containment becomes the path to host compromise.

    Post summary

    CVE-2026-26956 is a critical sandbox escape in vm2, enabling arbitrary command execution via a TypeError lever. The vulnerability is detailed and has been patched in version 3.10.5 and later releases.

    0000048
    102 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2022-36067 : CRITICAL SANDBOX ESCAPE ALERT 🚨 @NodeJS / vm2 A sandbox escape vulnerability has been disclosed in vm2 — a widely used Node.js library designed to securely execute untrusted JavaScript code in isolated environments. Risk Severity: Critical (CVSS 10.0, public PoC, active scanning, internet-exploitable) Impact: • Full sandbox escape • Arbitrary remote code execution • Host file system access • Theft of secrets, tokens, and environment variables • Cloud metadata access & container breakout • Complete compromise of application integrity Root Cause: CWE-269 (Improper Privilege Management) vm2 fails to properly isolate the host context when handling Error.prepareStackTrace. Unsanitized CallSite objects leak references to the host global object, allowing attackers to bypass the sandbox entirely. Attackers can: • Submit malicious JavaScript to vm2-backed execution endpoints • Override Error.prepareStackTrace inside the sandbox • Access host global, process, and native require() • Load child_process, fs, or network modules • Execute arbitrary system commands with host privileges Are You Affected? Vulnerable: vm2 < 3.9.11 Scope: Any internet-facing service executing untrusted JavaScript using vm2 (Online IDEs, CI/CD engines, plugin systems, multi-tenant platforms) Immediate Action Required: Update: Upgrade to vm2 3.9.11+ immediately (npm update vm2) Containment: Temporarily restrict access to all code execution endpoints Audit: Hunt for child_process, process, or require() usage originating from sandboxed contexts Sandbox isolation is completely broken. Any vulnerable vm2 deployment equals remote shell access. Patch without delay. 🛡️ #vm2 #nodejs #security #ostorlabCVE

    Post summary

    A critical sandbox escape in vm2 has been disclosed, with a public PoC and patch advisory urging immediate upgrade to v3.9.11+ to prevent remote code execution.

    00000103
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more