CVE-2023-30547Patch(vm2_project / vm2)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-01-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
vm2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-30: 1Mentions · 2026-05-06: 1Active Exploitation · 2026-05-06: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 101-3005-06
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Classification over time
DateTotalLabels
2026-01-301
Patch1
2026-05-061
Active Exploitation1
Full discourse2 posts
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    The post notes that CVE-2026-22709 is fixed in vm2 3.10.2 and lists several related sandbox escape CVEs, indicating a patch update rather than new exploit activity.

    10000133
    481 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    vm2 3.10.4 processed untrusted JavaScript on thousands of servers last week. This Node.js sandbox library pulls 1.3M+ weekly npm downloads. It's embedded in online coding platforms, automation pipelines, and SaaS apps designed to isolate code execution. CVE-2026-26956 was disclosed on May 6, 2026. It affects versions 3.10.4 and earlier. The fix landed in 3.10.5, with the latest release at 3.11.2. The vulnerability triggers on Node.js 25 when WebAssembly exception handling and JSTag are enabled - confirmed on v25.6.1. An attacker crafts a TypeError through Symbol-to-string conversion. This generates a host-side error object that leaks into the sandbox without sanitization. The error's constructor chain exposes Node.js internals, including the process object. From there, the attacker accesses require and child_process modules to execute arbitrary commands on the host. This marks the fourth critical sandbox escape in vm2: CVE-2026-22709 in January 2026, plus CVE-2023-30547, CVE-2023-29017, and CVE-2022-36067. vm2 maintainers have stated the library is no longer viable as a true sandbox. They recommend isolated-vm or Node's built-in permission model instead. A tool built for containment becomes the path to host compromise.

    Post summary

    CVE‑2026‑26956 enabled a sandbox escape in vm2, affecting thousands of production servers; attackers exploited it by inducing a TypeError that exposed Node internal objects, but a patch is available in version 3.10.5.

    0000048
    102 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more