CVE-2026-24118Disclosure(vm2_project / vm2)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-693CWE-749

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 13 signals
  • Disclosure: 13 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 7 mentions (2026-06-04); latest day: 2
  • 19 total mentions across 6 days

Affected systems

Products
vm2

Deep dive

Activity timeline19 mentions / 6d
02457Mentions · 2026-05-04: 3Mentions · 2026-05-07: 1Mentions · 2026-05-10: 4Mentions · 2026-06-04: 7Mentions · 2026-06-10: 2Mentions · 2026-08-27: 2PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-08-27: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-06-10: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-10: 3Technical Details · 2026-06-04: 6Technical Details · 2026-06-10: 105-0405-0705-1006-0406-1008-27
Signal classification5 categories
Disclosure
1368.4%
General
315.8%
Active Exploitation
15.3%
Patch
15.3%
Exploit
15.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-043
Disclosure3
2026-05-071
Active Exploitation1
2026-05-104
Disclosure2General2
2026-06-047
Disclosure7
2026-06-102
General1Patch1
2026-08-272
Disclosure1Exploit1
Full discourse19 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Malicious npm package vm2 (CVE-2026-24118) A package contains embedded malicious code that can intercept data and manipulate application behavior. 👉 Remove immediately — treat affected systems as compromised

    Post summary

    The text alerts that a malicious npm package vm2 (CVE-2026-24118) can intercept data and alter application behavior, urging immediate removal and treating affected systems as compromised.

    11010117
    122 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-Q8rk9MC [CRITICAL/PoC] Linked: CVE-2026-24118 CVE-2026-24118 🔗 https://exploitgrid.net/exploits/e875881a-186c-4291-be48-dfa1b8eda9a5

    Post summary

    The post shares a critical PoC for CVE‑2026‑24118, linking to exploitgrid where exploit code presumably resides, but offers no patch information or evidence of active exploitation.

    1000033
    38 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-39440 CVE-2026-24118 CVE-2023-20887 CVE-2023-20887 CVE-2023-20887 ..🧵👇

    Post summary

    The digest announces several newly disclosed CVEs without providing further technical details or indicators of exploitation.

    1000040
    38 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    New advisory to triage: CVE-2026-24118. VM2 Sandbox Breakout Through __lookupGetter__ Inventory first. Panic never helps.

    Post summary

    The post announces an advisory for CVE‑2026‑24118 involving a VM2 sandbox breakout via __lookupGetter__, but gives no explicit PoC, exploit code, remediation, or evidence of active exploitation.

    1000054
    315 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Status vs CVSS vs Attack Vector: CVE-2026-24118: Patched in 3.11.0 (vs CVSS 9.8 | Attack Vector `__lookupGetter__` + Buffer.apply → host Function.prototype) CVE-2026-43999: Patched in 3.11.0 (vs CVSS 9.9 | Attack Vector NodeVM builtin allowlist bypass (`builtin: ['*',…

    Post summary

    The brief update reports that CVE‑2026‑24118 and CVE‑2026‑43999 have been patched in version 3.11.0, providing CVSS scores and attack vector details for each vulnerability.

    1000038
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Sandbox That Never Was: CVE-2026-24118 Turns vm2 Into a Developer Supply Chain Weapon. Six critical vulnerabilities in the Node.js vm2 sandbox library CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956 expose full remote…

    Post summary

    The snippet announces six critical vulnerabilities in the Node.js vm2 sandbox library but offers no proof of exploitation, PoC, or patch details.

    1000027
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: A critical remote code execution vulnerability (CVE-2026-24118, CVSS 9.8) in the npm library vm2 (versions prior to 3.11.0) allows attackers to completely bypass the JavaScript sandbox isolation and execute arbitrary code on the…

    Post summary

    The post announces a critical remote code execution vulnerability (CVE-2026-24118) in the npm library vm2, detailing how attackers can bypass sandbox isolation to execute arbitrary code.

    1000048
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Sandbox Wall Cracked: CVE-2026-24118 Turns vm2 Into an Arbitrary Code Gateway A critical remote code execution vulnerability CVE-2026-24118, CVSS 9.8 in the npm library vm2 versions prior to 3.11.0 allows attackers to completely bypass the JavaScript sandbox isolation…

    Post summary

    The post announces a critical remote code execution vulnerability (CVE‑2026‑24118) in npm’s vm2 library, detailing its severity (CVSS 9.8) and the ability to bypass sandbox isolation in versions prior to 3.11.0, but it does not provide a PoC link, exploit code, or evidence of active exploitation.

    1000044
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six critical vulnerabilities in the Node.js vm2 sandbox library (CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956) expose full remote code execution on any system running untrusted code in vm2. CVSS 10.0. Disclosed May 3, 2026.…

    Post summary

    Six critical RCE vulnerabilities in the Node.js vm2 library have been announced with a CVSS score of 10.0. No PoC, exploit code, or mitigation details are provided.

    1000034
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    3 million · CVE-2026-24118 · < 3.11.0 → 9.8 The Sandbox Wall Cracked: CVE-2026-24118 Turns vm2 Into an Arbitrary Code Gateway

    Post summary

    CVE-2026-24118 allows arbitrary code execution via vm2 for versions < 3.11.0, with a high CVSS score of 9.8, but no PoC, exploit code, or patch details are provided.

    1000026
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    A critical remote code execution vulnerability (CVE-2026-24118, CVSS 9.8) in the npm library vm2 (versions prior to 3.11.0) allows attackers to completely bypass the JavaScript sandbox isolation and execute arbitrary code on the host system. The flaw defeats the entire…

    Post summary

    The announcement highlights a critical remote code execution flaw in npm’s vm2 library that allows bypassing the JavaScript sandbox and executing arbitrary code on the host system.

    1000038
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-24118 is the primary RCE vector, stemming from insufficient sanitization of cross-realm object interactions within the V8 engine. The remaining five CVEs target alternative escape chains through similar mechanisms.

    Post summary

    The text announces CVE-2026-24118 as the main RCE vector in V8 due to cross‑realm sanitization issues, noting five more CVEs that use similar escape chains.

    1000050
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-24118 (CVSS 9.8) — multiple products. CVE: CVE-2026-24118 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces the discovery of CVE‑2026‑24118, providing its severity rating and CVSS vector without mentioning any PoC, exploit code, active attacks, patches, or false‑positive discussion.

    1000025
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-24118-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    An advisory link for CVE-2026-24118 is posted, but the text lacks any substantive details about the vulnerability.

    0000016
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-24118 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text is a brief advisory noting the critical CVE‑2026‑24118, providing its CVSS score and severity, but lacking details on exploitation, PoC, or mitigation.

    0000026
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-24118 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory vm2 is an open source vm/sandbox for Node.js.

    Post summary

    Critical vulnerability (CVE-2026-24118) disclosed for the open source vm2 Node.js sandbox, with CVSS 9.8, but no exploit, patch, or false‑positive information is provided.

    0000055
    197 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited vm2 sandbox escape vulnerabilities (CVE-2026-22709, CVE-2026-24118) to execute arbitrary code and escalate privileges. Post-compromise lateral movement highlights how runtime segmentation can limit blast radius in containerized environments. #DevSecOps #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/vm2-nodejs-library-vulnerabilities-2026

    Post summary

    The text reports that attackers have actively exploited CVE‑2026‑22709 and CVE‑2026‑24118 for arbitrary code execution and privilege escalation, as detailed in the TRC analysis.

    0000057
    1.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24118 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which ca… https://www.cve.org/CVERecord?id=CVE-2026-24118 ----- Traducción: CVE-2026-24118 vm2… http://infoflow.cloud`

    Post summary

    CVE‑2026‑24118 impacts vm2 versions older than 3.11.0, enabling sandbox breakout for arbitrary code execution. No PoC, exploit, patch, or active exploitation is reported.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24118 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which ca… https://www.cve.org/CVERecord?id=CVE-2026-24118

    Post summary

    CVE-2026-24118 exposes a sandbox breakout in the Node.js vm2 package before version 3.11.0, enabling attackers to write malicious code, but no PoC, exploit details, or patch information are provided.

    00000180
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more