CVE-2026-22709Disclosure(vm2_project / vm2)

HIGHCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback function of `localPromise.prototype.then` is sanitized, but `globalPromise.prototype.then` is not sanitized. The return value of async functions is `globalPromise` object. Version 3.10.2 fixes the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-693CWE-913

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 44 mentions across 13 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 35 signals
  • Disclosure: 23 classified signals
  • General: 5 classified signals
  • Peaked 11d ago at 18 mentions (2026-01-28); latest day: 1
  • 44 total mentions across 13 days

Affected systems

Products
vm2

Deep dive

Activity timeline44 mentions / 13d
0591418Mentions · 2026-01-27: 5Mentions · 2026-01-28: 18Mentions · 2026-01-29: 3Mentions · 2026-01-30: 6Mentions · 2026-02-01: 2Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Mentions · 2026-06-04: 2Mentions · 2026-06-10: 1Mentions · 2026-08-18: 1PoC Mentioned / Linked · 2026-01-28: 4PoC Mentioned / Linked · 2026-02-01: 1Exploit Tool / Code · 2026-01-28: 2Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-01-27: 3Patch / Workaround · 2026-01-28: 9Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 3Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-01-27: 4Technical Details · 2026-01-28: 18Technical Details · 2026-01-29: 3Technical Details · 2026-01-30: 4Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-06-04: 1Technical Details · 2026-08-18: 101-2701-2801-2901-3002-0102-0302-0402-0505-0605-0706-0406-1008-18
Signal classification5 categories
Disclosure
2352.3%
Patch
1227.3%
General
511.4%
Active Exploitation
36.8%
PoC
12.3%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-275
Disclosure3Patch2
2026-01-2818
Active Exploitation1Disclosure9General1Patch6PoC1
2026-01-293
Disclosure1Patch2
2026-01-306
Disclosure3General1Patch2
2026-02-012
Disclosure1General1
2026-02-031
General1
2026-02-041
Disclosure1
2026-02-051
Disclosure1
2026-05-061
Active Exploitation1
2026-05-072
Active Exploitation1Disclosure1
2026-06-042
Disclosure2
2026-06-101
General1
2026-08-181
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🚨 A critical flaw in the vm2 Node.js library lets attackers escape the sandbox and run code on the host system. Tracked as CVE-2026-22709 (CVSS 9.8), the issue stems from improper Promise handler sanitization. 🔗 How the flaw works → https://thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.html

    Post summary

    The post announces a critical sandbox escape flaw (CVE-2026-22709) in the vm2 Node.js library, rated CVSS 9.8, enabling attackers to run code on the host system via improper Promise handler sanitization.

    221167129.5K
    1.0M followersView on X
  • yousukezan@yousukezan
    Disclosure

    Node.js向けサンドボックスvm2に致命的な欠陥が見つかり、隔離環境を突破して任意コード実行が可能になることが判明した。 問題はPromise処理におけるコールバックの無害化が不完全だった点にあり、CVE-2026-22709として公開された。 CVSSは9.8で、認証やユーザー操作を必要とせずネットワーク経由で悪用可能と評価されている。 vm2ではローカルとホストで異なるPromiseを用いて隔離を実現しているが、非同期関数が返すglobalPromiseではthenやcatchの処理に欠陥があり、http://Function.prototype.callの差し替えによりsanitize処理を回避できた。 結果としてホスト側のErrorオブジェクト経由でFunctionコンストラクタに到達し、サンドボックス外でコード実行が成立する。 修正は2026年1月26日公開の3.10.2でReflect.applyを用いる形に変更された。 ただしvm2は2023年以降非推奨とされ、過去にも多数の脱出事例があるため、攻撃者制御コードの実行用途には根本的に不向きとされている。 https://www.endorlabs.com/learn/cve-2026-22709-critical-sandbox-escape-in-vm2-enables-arbitrary-code-execution

    Post summary

    A critical sandbox escape flaw (CVE‑2026‑22709) in Node.js’s vm2 module was disclosed, detailing the exploit technique and providing a patch.

    0201011.4K
    11.4K followersView on X
  • Henry Raúl Glez Brito@henryraul
    General

    Referencias para profundizar sobre vulnerabilidad crítica en vm2 (Node.js): https://www.cve.org/CVERecord?id=CVE-2026-22709 https://www.npmjs.com/package/vm2 https://blog.segu-info.com.ar/2026/01/vulnerabilidad-critica-en-vm2-nodejs.html https://github.com/patriksimek/vm2/security/advisories/GHSA-99p7-6v5w-7xg8

    Post summary

    El mensaje lista enlaces de referencia a una vulnerabilidad crítica de vm2, sin proporcionar detalles sobre PoC, exploits, mitigaciones ni confirmación de explotación activa.

    03031103
    11.3K followersView on X
  • SecDim@secdim
    General

    vm2 should not be relied upon as a sole security control. We promised a write-up. Here it is. Using the recent vm2 escape (CVE-2026-22709) as a case study, we ask: Can a #JavaScript sandbox ever be treated as a security boundary? Link below #appsec #securecoding #security https://t.co/LEV478zJPm

    Post summary

    The tweet highlights a forthcoming write-up on the vm2 escape vulnerability (CVE-2026-22709) but lacks specific technical details, exploit code, or patches.

    10120164
    279 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    🚨 ثغرة خطيرة في مكتبة vm2 لـ Node.js تم اكتشاف ثغرة خطيرة تسمح بتجاوز الـ sandbox في مكتبة vm2، وهي مكتبة Node.js شائعة تستخدم لعزل وتنفيذ الأكواد غير الموثوقة. هذا الخلل، والمُعرف بـ CVE-2026-22709، يمنح المهاجمين القدرة على تشغيل تعليمات برمجية ضارة خارج البيئة الآمنة. 💡 خطوات الحماية: - حدث مكتبة vm2 إلى أحدث إصدار متوفر. - قم بمراجعة أكواد التطبيقات التي تستخدم vm2 للتأكد من عدم وجود نقاط ضعف. - طبق مبدأ تقليل الصلاحيات للعمليات التي تنفذ أكواد غير موثوقة. 🔗 https://cybersecuritynews.com/vm2-sandbox-vulnerability/ #الأمن_السيبراني #Nodejs #vm2 #Vulnerability #CVE

    Post summary

    The post announces a critical sandbox‑escape vulnerability (CVE‑2026‑22709) in the Node.js vm2 library, details how attackers could bypass isolation, and recommends upgrading the library and applying least‑privilege controls.

    0003071
    51 followersView on X
  • NanoVMs@nanovms
    Disclosure

    with a million weekly downloads on npm, vm2 is back out of retirement with yet another sandbox escape - CVE-2026-22709 - if you need stronger security - consider shipping as a nanos unikernel && avail yourself of the pledge/unveil klib https://docs.ops.city/ops/klibs#sandbox https://t.co/GUEj6pcBez

    Post summary

    The tweet announces a sandbox escape in vm2 (CVE‑2026‑22709) and suggests a workaround using nanos unikernels and pledge/unveil klibs, but provides no PoC, exploit code, or evidence of active exploitation.

    01020296
    2.0K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    vm2、また問題です。 本来は隔離されているJavaScriptが、そのセキュリティ境界を破って、サーバー側まで到達できてしまう脆弱性が見つかりました。 CVE-2026-47698。 対象は 0.0.1〜3.11.5。3.11.6で修正されています。 ただ、今回のCVEだけを見るより、そもそもvm2が何なのかを見た方が面白い。 vm2は、Node.jsの中で「外から渡されたJavaScript」を隔離して実行するためのモジュールです。 たとえば、 ・ワークフローの途中でユーザーがJavaScriptを書く ・ローコード製品で独自の式や処理を書く ・プラグインやカスタムコードを実行する ・最近なら、AIエージェントやLLMが生成したコードを実行する そんな場所で使われます。 別の仮想マシンやコンテナを立てるのではなく、同じNode.jsプロセスの中でコードを隔離して動かせる。 軽い。速い。組み込みやすい。 だから広がりました。 ところが、このvm2。 2023年に一度、メンテナンス終了が宣言されています。 理由は単なる人手不足ではありません。 サンドボックスのセキュリティ境界を破られる問題が相次ぎ、安全に維持するのが難しいとして終了した。 代替として isolated-vm への移行まで勧められました。 普通なら、ここで終わったOSSです。 でも終わらなかった。 利用する製品やサービスが多く、今でも週100万回近くダウンロードされている。 そして2025年、元のオーナーが開発を再開しました。 ただし、復活したからといって、根本の構造が別物になったわけではありません。 2026年に入ってからも問題は続いています。 1月には CVE-2026-22709。 5月の3.11.0では、13件のSecurity Advisoryに対応。 そして8月、またvm2です。 今回の3.11.6では、さらに5件のSecurity Advisoryに対応。 その一つが、昨日のAikido Intelにも上がってきた CVE-2026-47698 です。 しかも、このCVE番号自体は5月に予約されていました。 5月に大量の問題を修正して終わったわけではない。 その後も調査と修正が続き、3か月後にまた新しい問題が表に出てきた。 気になるのは、個々のCVEより、この流れです。 一度は「安全に維持するのが難しい」として終了した。 需要が消えず、復活した。 そして復活後も、セキュリティ境界を破られる問題が続いている。 さらに今は、昔より「外から来たコードを実行する」場面が増えています。 AIがコードを書くようになったからです。 「うちはvm2なんて使っていない」と思っていても、自分でnpm installしたとは限りません。 ワークフロー製品、ローコード、プラグイン、コード実行機能。 その内側に入っている可能性があります。 確認したいのは、 自社のサービスで、ユーザーやAIが作ったJavaScriptを実行できる場所はどこか。 その下で、何を使って隔離しているのか。 AI時代になって新しい問題が突然生まれたというより、 昔から難しかった「信頼できないコードを、どこまで安全に実行できるのか」という問題が、急に重要になってきたように見えます。 https://github.com/patriksimek/vm2/releases/tag/3.11.6 #vm2 #脆弱性 #AppSec #AIセキュリティ #サンドボックス #NodeJS #AikidoIntel

    Post summary

    CVE-2026-47698 reveals that vm2 allows sandbox escape by JavaScript, affecting versions 0.0.1–3.11.5, and has been patched in 3.11.6 along with other related advisories.

    10010467
    830 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    vm2 JavaScript サンドボックスの脆弱性 CVE-2026-22709 が FIX:サニタイズ不備による RCE の恐れ https://iototsecnews.jp/2026/01/27/critical-vm2-flaw-lets-attackers-bypass-sandbox-and-execute-arbitrary-code-in-node-js/ JavaScript の隔離実行ライブラリとして広く利用されている vm2 に、サンドボックスが突破され、ホストシステム上での任意のコード実行に至る、きわめて深刻な脆弱性 CVE-2026-22709 が発見されました。この脆弱性を悪用する攻撃者は、認証やユーザーの操作を一切必要とせず、ネットワーク経由でリモートから攻撃が可能なため、CVSS スコアは 9.8 (Critical) と評価されています。 この脆弱性は、npm 上の膨大なプロジェクトに影響を及ぼす可能性があり、特にユーザー投稿のスクリプトやプラグインをサンドボックス内で実行している、テンプレートエンジン/セキュリティ分析ツールなどのプラットフォームにとって致命的な脅威となり得ます。ご利用のチームは、ご注意ください。 #CVE202622709 #vm2JavaScript #Vulnerability

    Post summary

    The article announces a critical RCE vulnerability (CVE‑2026‑22709) in the vm2 JavaScript sandbox, noting remote exploitation without authentication and a CVSS score of 9.8, but provides no PoC, exploit code, or evidence of active attacks.

    01001152
    483 followersView on X
  • Checkmarx Zero@CheckmarxZero
    Disclosure

    🚨 CVE-2026-22709 | VM2 — Sandbox Escape Leads To RCE A new #RCE vulnerability has been identified in #vm2 prior to version 3.10.2. An incomplete sanitization of critical elements is bypassable, allowing attackers to escape the sandbox and execute arbitrary code. This vulnerability can result in critical code injection risks. Stay safe by updating vm2 to version 3.10.2. #AppSec https://devhub.checkmarx.com/cve-details/CVE-2026-22709/

    Post summary

    A new RCE vulnerability (CVE‑2026‑22709) in vm2 was announced, detailing incomplete sanitization that enables sandbox escape and arbitrary code execution; updating to v3.10.2 mitigates the issue.

    0101089
    223 followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Critical Vulnerability Alert Node.js vm2 sandbox escape CVE-2026-22709 (CVSS 9.8) allows arbitrary code execution on the host. Update immediately and review isolation controls. #CyberSecurity #NodeJS #OpenSource https://t.co/k0RMvxVa7w

    Post summary

    A critical sandbox escape vulnerability in Node.js vm2 (CVE-2026-22709) with a CVSS of 9.8 is announced; users are advised to apply the available patch immediately.

    0002066
    249 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Critical vulnerability CVE-2026-22709 in vm2 NodeJS sandbox allows attackers to escape and run arbitrary code by bypassing Promise callback sanitization in v3.10.0. Exploit is trivial to use on affected versions. #NodeJS #SandboxEscape #USA https://ift.tt/MW3p1vo

    Post summary

    Critical CVE-2026-22709 in vm2 NodeJS sandbox allows attackers to escape and run arbitrary code by bypassing Promise callback sanitization in v3.10.0; the exploit is trivial but no PoC, patch, or evidence of active exploitation is provided.

    00020177
    3.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Sandbox That Never Was: CVE-2026-24118 Turns vm2 Into a Developer Supply Chain Weapon. Six critical vulnerabilities in the Node.js vm2 sandbox library CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956 expose full remote…

    Post summary

    The article announces six critical vulnerabilities in the Node.js vm2 sandbox library, framing them as a developer supply chain risk, but does not provide any PoC, exploit code, patch, or detailed technical information.

    1000027
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six critical vulnerabilities in the Node.js vm2 sandbox library (CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956) expose full remote code execution on any system running untrusted code in vm2. CVSS 10.0. Disclosed May 3, 2026.…

    Post summary

    Six critical RCE vulnerabilities were disclosed in the Node.js vm2 sandbox library, each graded CVSS 10.0, with no known exploits or mitigation details mentioned yet.

    1000034
    239 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en Node.js ❗ CVE-2026-22709 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-node-js/ https://t.co/i4AkRryAN4

    Post summary

    The tweet announces a Node.js vulnerability (CVE‑2026‑22709) and directs readers to a CERT page for more information, but no additional details about the flaw, exploitation, or mitigation are provided.

    00001146
    6.6K followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Patch

    While CVE-2026-22709 has been addressed in vm2 version 3.10.2, it's the latest in a steady stream of sandbox escapes that have plagued the library in recent years. This includes CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547, CVE-2023-32314, CVE-2023-37466, and CVE-2023-37903.

    Post summary

    The text announces that CVE-2026-22709 is fixed in vm2 v3.10.2, listing other similar sandbox escape CVEs but without providing exploit details or patchwork.

    10000133
    481 followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    General

    The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 🚨 9.8 out of 10.0 💥 on the CVSS scoring system.

    Post summary

    The statement only identifies CVE-2026-22709 and its high CVSS score, without further technical or operational context.

    1000043
    481 followersView on X
  • Adam Goss@gossy_84
    Disclosure

    🗞️ A critical vulnerability (CVE-2026-22709) with a 9.8 CVSS score has been discovered in the popular vm2 library, allowing attackers to bypass security boundaries. This flaw enables untrusted code to escape its sandboxed environment and execute arbitrary commands on the host OS.

    Post summary

    A newly discovered critical vulnerability (CVE-2026-22709) in the vm2 library allows attackers to bypass sandbox boundaries and execute arbitrary commands on the host OS.

    1000072
    1.5K followersView on X
  • SOCRadar®@socradar
    Patch

    🚨 Critical sandbox escape in #vm2 Node.js library (CVE-2026-22709, CVSS 9.8) allows attackers to break out of JavaScript sandboxes and execute code on the host. 🔹 Affects vm2 ≤ 3.10.1 🔹 #RCE risk 🔹 Patch available (3.10.2+) https://socradar.io/blog/cve-2026-22709-vm2-sandbox-escape-vulnerability/

    Post summary

    A critical sandbox escape flaw (CVE-2026-22709) in vm2 allows RCE; a patch is available (3.10.2+). No active exploitation or PoC is reported.

    00010202
    5.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical vm2 Sandbox Escape Bug Enables Arbitrary Code Execution (CVE-2026-22709) A critical flaw (CVE-2026-22709) in the vm2 Node.js sandbox library allows attackers to break out of the sandbox and execute arbitrary code on the underlying host system, a high-impact risk for apps that run “untrusted” JavaScript. Update vm2 immediately and treat any exposed sandbox execution path as potential RCE until fully patched and validated. 🎯 Target: Global/Node.js & Applications Using vm2 #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/critical-vm2-vulnerability-allows-sandbox-escape-and-arbitrary-code-execution

    Post summary

    The alert reports a critical sandbox escape vulnerability in vm2 that enables arbitrary code execution, and it stresses the need for immediate patching.

    0001064
    196 followersView on X
  • motch | ソフトウェアエンジニア👨‍💻@motch_dev
    Patch

    🚨【緊急】Node.js「vm2」にCVSS 10.0の致命的脆弱性(CVE-2026-22709) v3.10.1以下で信頼できないコードを実行している場合、サンドボックスを突破されホストを乗っ取られる恐れがあります。 ✅対策: v3.10.2へ即アップデート ✅推奨: isolated-vmやgVisor等による多層防御への移行 該当するvm2を利用されていませんか?即座にアップデートを! #CybersecurityNews #Nodejs

    Post summary

    A critical CVE-2026-22709 affects Node.js vm2 (v3.10.1 or lower), enabling sandbox bypass and host takeover; users are urged to upgrade to v3.10.2 and adopt multi‑layer defenses.

    10000126
    254 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more