
While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.
Post summary
The post notes CVE-2026-22709 was fixed in vm2 3.10.2 and lists other sandbox‑escape CVEs, indicating a patch exists but no PoC or active exploitation is mentioned.
