TheTechWorldPodcast[verified]@TheTechWorldPodDisclosure
Vulnerability CVE‑2023‑37903 was discovered in July 2023, prompting the project's discontinuation. It was later revived and its security page updated to note active maintenance of vm2 3.x versions.
TheTechWorldPodcast[verified]@TheTechWorldPodPatch
The text states that CVE-2026-22709, a sandbox escape in vm2, is fixed in version 3.10.2 and lists several related sandbox‑escape CVEs.
DFIR Lab[verified]@DFIR_LabPatch
CVE-2023-37903 in vm2 Node.js sandbox is disclosed with detailed bypass mechanics, and the flaw is patched in version 3.11.4.
SecAlerts@SecAlertsCoPatch
The tweet announces a severe network‑exploitable sandbox escape in vm2, detailing the technical flaw and urging users to update the library.
SecAlerts@SecAlertsCoDisclosure
The tweet announces a new Critical CVE‑2026‑47137 sandbox escape in vm2 (npm), noting it bypasses a prior fix, is unauthenticated with no interaction needed, and carries a CVSS 10.0 score, urging users to treat it as critical.
DailyCVE@dailycveDisclosure
The tweet announces a critical sandbox escape vulnerability in vm2 (Node.js) identified as CVE-2023-37903, describing how the exploit leverages custom Inspect and WebAssembly.