Exploitation ongoing with high activity in latest observed window (3 mentions)
Immediate actions
Patch vm2_project vm2 systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.
🚨 تحذير أمني عاجل لمطوري Node.js!
اكتشاف ثغرة Sandbox Escape في مكتبة vm2 الشهيرة (CVE-2023-29017) تسمح للمهاجمين بالسيطرة الكاملة على الخادم المضيف.
🛠 التحليل التقني:
- النوع: تنفيذ أوامر عن بُعد (RCE).
- الخطورة: 10/10 (حرجة جداً).
- الآلية: استغلال ثغرات في معالجة الكائنات لتجاوز حدود العزل البرمجي.
🎯 لماذا هذا مهم؟
إذا كان تطبيقك يسمح بتشغيل نصوص برمجية من المستخدمين (مثل أدوات الأتمتة أو المحررات البرمجية) ويستخدم vm2، فأنت عرضة للاختراق الفوري.
⚠️ التوصية:
مكتبة vm2 أصبحت الآن 'End of Life'. يُنصح بالانتقال فوراً إلى البدائل مثل isolated-vm أو استخدام الحاويات (Containers) لضمان الأمان.
التفاصيل الكاملة في مقالنا الجديد على Glitch4Techs 👇
#أمن_المعلومات #برمجة #NodeJS#CyberSecurity#Glitch4Techs
🔗 اقرأ المقال كاملاً عبر موقعنا:
Post summary
The post announces a critical RCE in the vm2 Node.js library (CVE‑2023‑29017), warns about immediate risk, and advises moving to alternatives.
🚨 تحذير أمني عاجل لمطوري Node.js!
اكتشاف ثغرة Sandbox Escape في مكتبة vm2 الشهيرة (CVE-2023-29017) تسمح للمهاجمين بالسيطرة الكاملة على الخادم المضيف.
🛠 التحليل التقني:
- النوع: تنفيذ أوامر عن بُعد (RCE).
- الخطورة: 10/10 (حرجة جداً).
- الآلية: استغلال ثغرات في معالجة الكائنات لتجاوز حدود العزل البرمجي.
🎯 لماذا هذا مهم؟
إذا كان تطبيقك يسمح بتشغيل نصوص برمجية من المستخدمين (مثل أدوات الأتمتة أو المحررات البرمجية) ويستخدم vm2، فأنت عرضة للاختراق الفوري.
⚠️ التوصية:
مكتبة vm2 أصبحت الآن 'End of Life'. يُنصح بالانتقال فوراً إلى البدائل مثل isolated-vm أو استخدام الحاويات (Containers) لضمان الأمان.
التفاصيل الكاملة في مقالنا الجديد على Glitch4Techs 👇
#أمن_المعلومات #برمجة #NodeJS#CyberSecurity#Glitch4Techs
🔗 اقرأ المقال كاملاً عبر موقعنا:
Post summary
The post discloses a critical CVE‑2023‑29017 RCE in vm2 with detailed technical info and urges developers to drop the library and migrate to alternatives or containers.
While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.
Post summary
CVE‑2026‑22709 is fixed in vm2 v3.10.2, and the library has suffered a series of sandbox escape vulnerabilities over recent years.
The post merely announces a critical sandbox escape vulnerability (CVE‑2023‑29017) for vm2, without offering any PoC, exploit, or mitigation information.
vm2 3.10.4 processed untrusted JavaScript on thousands of servers last week.
This Node.js sandbox library pulls 1.3M+ weekly npm downloads. It's embedded in online coding platforms, automation pipelines, and SaaS apps designed to isolate code execution.
CVE-2026-26956 was disclosed on May 6, 2026. It affects versions 3.10.4 and earlier. The fix landed in 3.10.5, with the latest release at 3.11.2.
The vulnerability triggers on Node.js 25 when WebAssembly exception handling and JSTag are enabled - confirmed on v25.6.1.
An attacker crafts a TypeError through Symbol-to-string conversion. This generates a host-side error object that leaks into the sandbox without sanitization.
The error's constructor chain exposes Node.js internals, including the process object. From there, the attacker accesses require and child_process modules to execute arbitrary commands on the host.
This marks the fourth critical sandbox escape in vm2: CVE-2026-22709 in January 2026, plus CVE-2023-30547, CVE-2023-29017, and CVE-2022-36067.
vm2 maintainers have stated the library is no longer viable as a true sandbox. They recommend isolated-vm or Node's built-in permission model instead.
A tool built for containment becomes the path to host compromise.
Post summary
CVE-2026-26956 facilitated sandbox escape in vm2, compromising thousands of servers last week. A remediation patch is available in version 3.10.5.
🚨 CVE-2023-29017 : CRITICAL SANDBOX BYPASS RCE ALERT 🚨 NodeJS
A sandbox escape vulnerability has been disclosed in the vm2 Node.js library — a security-critical component used to execute untrusted JavaScript code in isolated environments.
Risk Severity:
Critical (CVSS 9.8+, active exploitation, public PoCs, internet-facing abuse observed)
Impact:
Arbitrary remote code execution on the host server
Complete sandbox bypass
Full compromise of Node.js applications
Theft of secrets, credentials, and environment variables
Persistent backdoors, ransomware, crypto-miners
Lateral movement to connected services
Root Cause:
CWE-254 (Improper Security Control / Sandbox Escape)
vm2 fails to properly isolate Error.prepareStackTrace during unhandled asynchronous errors, allowing sandboxed code to access host objects, pollute prototypes, and escape into the host execution context.
Attackers can:
Submit malicious JavaScript to any vm2-backed execution endpoint
Trigger unhandled async errors (Promise rejection / async throw)
Abuse error stack handling to access host globals
Execute arbitrary JavaScript and OS commands
Fully compromise the underlying Node.js process
Are You Affected?
Vulnerable: vm2 < 3.9.15
Scope: Any application executing user-supplied JavaScript via vm2
Online REPLs & code playgrounds
Serverless / function platforms
CMS scripting engines
Data pipelines with custom JS logic
Chatbots or APIs evaluating JavaScript
Immediate Action Required:
Update: Upgrade to vm2 3.9.15+ immediately
Mitigation: Disable vm2 execution until patched if upgrade is delayed
Audit:
Hunt for unhandledRejection events in vm2 contexts
Monitor Node.js processes for unexpected child_process, fs, or outbound traffic
Investigate attempts to access Error.prepareStackTrace, Function, process, or prototype manipulation
vm2’s core security boundary is broken. Any exposed instance should be treated as an active RCE target. Patch without delay. 🛡️
#nodejs#security#ostorlabCVE
Post summary
Critical sandbox escape RCE in vm2 is being actively exploited; immediate patch to 3.9.15+ is required.