CVE-2026-26956Disclosure(vm2_project / vm2)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-653

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 34 mentions across 11 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 30 signals
  • Disclosure: 9 classified signals
  • Peaked 7d ago at 9 mentions (2026-05-07); latest day: 2
  • 34 total mentions across 11 days

Affected systems

Products
vm2

Deep dive

Activity timeline34 mentions / 11d
02579Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-06: 5Mentions · 2026-05-07: 9Mentions · 2026-05-08: 6Mentions · 2026-05-09: 1Mentions · 2026-05-11: 5Mentions · 2026-05-14: 1Mentions · 2026-05-24: 1Mentions · 2026-05-26: 1Mentions · 2026-06-04: 2PoC Mentioned / Linked · 2026-05-04: 2PoC Mentioned / Linked · 2026-05-06: 2PoC Mentioned / Linked · 2026-05-07: 4PoC Mentioned / Linked · 2026-05-08: 2PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-26: 1Exploit Tool / Code · 2026-05-04: 1Exploit Tool / Code · 2026-05-06: 2Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-24: 1Active Exploitation · 2026-05-07: 3Active Exploitation · 2026-05-08: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-05-07: 6Patch / Workaround · 2026-05-08: 4Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 4Technical Details · 2026-05-07: 8Technical Details · 2026-05-08: 6Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 4Technical Details · 2026-05-14: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-04: 105-0405-0505-0605-0705-0805-0905-1105-1405-2405-2606-04
Signal classification6 categories
Disclosure
926.5%
PoC
926.5%
Patch
720.6%
Active Exploitation
411.8%
General
38.8%
Exploit
25.9%
Referenced assets21 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-042
Disclosure1Exploit1
2026-05-051
Patch1
2026-05-065
Disclosure1Patch2PoC2
2026-05-079
Active Exploitation3Disclosure1Exploit1Patch2PoC2
2026-05-086
Active Exploitation1Disclosure1Patch2PoC2
2026-05-091
Disclosure1
2026-05-115
Disclosure1General3PoC1
2026-05-141
Disclosure1
2026-05-241
PoC1
2026-05-261
PoC1
2026-06-042
Disclosure2
Full discourse20 posts
  • DFIR Radar@DFIR_Radar
    PoC

    CVE-2026-26956 (CVSS 9.8) enables full sandbox escape in vm2 3.10.4 via WebAssembly exception handling, leading to host RCE in Node.js 25. PoC available. Upgrade to vm2 3.10.5+ immediately and audit http://VM.run() calls with untrusted input. #DFIR_Radar https://t.co/ImuJ6sVnqe

    Post summary

    CVE‑2026‑26956 is a CVSS 9.8 vulnerability in vm2 that allows sandbox escape through WebAssembly exception handling, leading to host RCE in Node.js 25. A PoC exists, and the advisory urges upgrading to vm2 3.10.5+ and reviewing untrusted WebAssembly calls.

    10080583
    1.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Node.jsのvm2サンドボックスライブラリに複数の重大(Critical)な脆弱性。CVE-2026-26956、CVE-2026-24120、CVE-2026-24781、CVE-2026-24118の4件で、いずれもCVSSスコア9.8。修正版提供あり。 https://securityonline.info/vm2-sandbox-escape-9-8-cvss-rce-vulnerabilities-node-js/

    Post summary

    Four critical vm2 sandbox CVEs (score 9.8) are disclosed, and a patch is now available.

    01060865
    7.6K followersView on X
  • Qualys@qualys
    PoC

    A critical vm2 sandbox escape vulnerability (CVE-2026-26956) could allow attackers to break out of the Node.js sandbox and execute arbitrary code on the host system. With public PoC code available, organizations using vm2 should act quickly to assess exposure and patch impacted environments. Upgrade guidance, affected versions, and detection details are now available in our latest blog. Read more and stay ahead of emerging threats: https://bit.ly/4cYrTnT #CyberSecurity #NodeJS #VulnerabilityManagement

    Post summary

    The post announces a critical sandbox escape flaw in vm2, confirms the availability of a public PoC, and urges swift patching, making the primary focus the PoC.

    01032570
    34.2K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Adversaries are exploiting CVE-2026-26956 in vm2 to achieve RCE via WebAssembly. Learn how this 9.8 CVSS escape bypasses Node.js isolation layers. #NodeJS #CyberSecurity #vm2 #ZeroDay #WASM #InfoSec #SandboxEscape #AppSec #RCE #Javascript #CVE https://securityexpress.info/vm2-sandbox-escape-cve-2026-26956-nodejs-wasm-vulnerability/ https://t.co/B0nJZo3LSm

    Post summary

    Adversaries are actively exploiting CVE‑2026‑26956 in Node.js’s vm2 sandbox to achieve remote code execution through WebAssembly, with a 9.8 CVSS score, although no patch or PoC details are mentioned.

    01041606
    12.5K followersView on X
  • SOCRadar®@socradar
    Disclosure

    Sandboxes should keep the mess contained. CVE-2026-26956 is a critical escape in the Node.js vm2 library (v3.10.4) leading to arbitrary code execution in the host process. Learn how it works and how to mitigate the risk today. Read more: https://hubs.la/Q04fX3YL0 #NodeJS #CyberSecurity

    Post summary

    The post discloses CVE-2026-26956 as a critical escape flaw in Node.js vm2 v3.10.4 that allows arbitrary code execution, directing readers to additional resources for mitigation.

    00032253
    6.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    vm2 Node.js Sandbox ライブラリの 11 件の脆弱性:任意のコード実行などの可能性 https://iototsecnews.jp/2026/05/07/critical-vm2-node-js-library-flaws-enable-arbitrary-code-execution-attacks/ 今回の脆弱性群の主な原因は、サンドボックスとホストを繋ぐブリッジ機構において、オブジェクト参照の管理が不完全だったことにあります。 CVE-2026-26956 のように JavaScript 内部の例外処理の悪用を許すものや、 CVE-2026-43999 のように設定上のロジック不備を露呈するものにより、本来は隔離されるべきホスト側の機能へのアクセスが可能になっています。 また CVE-2026-44007 のように、特定の条件下でライブラリ自身がサンドボックス内に注入されてしまう設計上の課題も指摘されています。 CVE-2026-44008 や CVE-2026-44009 など未修正の問題も残っており、言語仕様の深層を防御することの難しさが浮き彫りにされています。ご利用のチームは、ご注意ください。 #CVE202624118 #CVE202624120 #CVE202624781 #CVE202626332 #CVE202626956 #CVE202643997 #CVE202643999 #CVE202644005 #CVE202644006 #CVE202644007 #CVE202644008 #CVE202644009 #Nodejs #vm2 #Vulnerability

    Post summary

    The article announces 11 vm2 Node.js library CVEs that could allow arbitrary code execution due to sandbox bridge vulnerabilities, providing technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    01001144
    491 followersView on X
  • Cyber_Lens@Aiz_Cyber
    PoC

    🚨 Critical vm2 Sandbox Escape ⚠️ Attackers Can Execute Code on Host Systems (CVE-2026-26956) — PoC Released, Upgrade Now! Check Description 👇 #CyberSecurity #NodeJS #Vulnerability #aiz_cyber https://t.co/GusLdaF2f8

    Post summary

    The tweet announces a critical vm2 sandbox escape (CVE-2026-26956) that permits code execution on host systems, provides a PoC, and urges users to upgrade to mitigate the risk.

    0001188
    40 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【vm2 CVE-2026-26956、Node.jsサンドボックス脱出でホストコード実行の恐れ】 BleepingComputerは、Node.js向けサンドボックスライブラリvm2のCVE-2026-26956について、攻撃者がサンドボックスを脱出し、ホスト上で任意コードを実行できると報じています。影響が確認されたのはvm2 3.10.4とNode.js 25環境です。 vm2は、信頼できないJavaScriptを安全に実行するためにSaaS、オンラインIDE、自動化、プラグイン実行基盤などで使われることがあります。サンドボックスが破られると、テナント隔離やユーザーコード隔離が崩れ、環境変数、クラウド認証情報、内部APIへ到達する恐れがあります。 防御側は、vm2を3.10.5以降へ更新し、可能なら最新安定版へ移行してください。untrusted code execution環境では、ライブラリ更新だけでなく、短命コンテナ、egress制限、秘密情報の環境変数投入削減も必要です。 #vm2 #Nodejs #CVE202626956 #SandboxEscape #DevSecOps #AppSec https://www.bleepingcomputer.com/news/security/critical-vm2-sandbox-bug-lets-attackers-execute-code-on-hosts/

    Post summary

    BleepingComputer reports the CVE-2026-26956 sandbox‑escape vulnerability in vm2, advises users to update to 3.10.5 or newer, and highlights host code execution risks.

    00002323
    3.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Node.js vm2 Sandbox Escape (CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956) A series of critical vulnerabilities in the vm2 library allows unauthenticated attackers to bypass the sandbox environment. By exploiting flaws in object sanitization and error handling (such as SuppressedError), an attacker can "break out" of the virtual machine and execute arbitrary commands directly on the host operating system. 👉 Affected: vm2 < 3.11.0, <3.10.5 | Upgrade to 3.11.0, 3.10.5

    Post summary

    Critical vm2 sandbox escape vulnerabilities expose the host to arbitrary command execution; users are advised to upgrade to the patched library versions immediately.

    0002092
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Sandbox That Never Was: CVE-2026-24118 Turns vm2 Into a Developer Supply Chain Weapon. Six critical vulnerabilities in the Node.js vm2 sandbox library CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956 expose full remote…

    Post summary

    The article announces six critical CVEs in the Node.js vm2 sandbox library, underscoring potential supply‑chain risks, but offers no proof‑of‑concept, exploit code, patch details, or technical breakdown.

    1000027
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six critical vulnerabilities in the Node.js vm2 sandbox library (CVE-2026-24118, CVE-2026-22709, CVE-2026-24120, CVE-2026-24781, CVE-2026-26332, CVE-2026-26956) expose full remote code execution on any system running untrusted code in vm2. CVSS 10.0. Disclosed May 3, 2026.…

    Post summary

    Six critical RCE vulnerabilities were disclosed in the Node.js vm2 sandbox library, all rated CVSS 10 and unpatched at the time of disclosure.

    1000034
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-26956 (CVSS 9.8) — multiple products. CVE: CVE-2026-26956 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE‑2026‑26956 as a critical vulnerability with a CVSS score of 9.8, but provides no PoC, exploit, or patch information.

    1000027
    197 followersView on X
  • RST Cloud@rst_cloud
    PoC

    #threatreport #LowCompleteness CVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25 | 07-05-2026 Source: https://socradar.io/blog/cve-2026-26956-vm2-sandbox-escape-rce-node-js-25/ Key details below ↓ 🎯Victims: Plugin execution systems, Continuous integration platforms, Automation platforms, Workflow platforms, Services running untrusted javascript 🔓CVEs: CVE-2026-26956 \[[Vulners](https://vulners.com/cve/CVE-2026-26956)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown 📚TTPs: ⚔️Tactics: 2 🛠️Technics: 0 🤖LLM extracted TTPs:` T1059.007 🧨IOCs: - File: 3 💽Software: Node.js, Linux 🔠Functions: Symbol 📜Programming Languages: javascript 💻Platforms: x64 #threatreport: CVE-2026-26956 is a critical vulnerability in the vm2 library, which is used for sandboxing untrusted JavaScript code in Node.js applications. This issue allows an attacker to escape the sandbox environment provided by vm2 version 3.10.4 and gain arbitrary code execution (RCE) in the host Node.js process, which has been assigned a CVSS score of 9.8, indicating its severity. The vulnerability specifically affects Node.js version 25, with confirmed exploitation on Node.js v25.6.1 running on x64 Linux. Attackers exploit this vulnerability through a manipulation of WebAssembly exception handling. Vm2 primarily relies on JavaScript-level controls for sandboxing and error handling, but CVE-2026-26956 bypasses these protections utilizing a WebAssembly construct known as try_table in conjunction with a JSTag catch handler. This allows attackers to intercept JavaScript exceptions at a level that circumvents vm2's typical error management processes. Ultimately, they can use the resulting error object to access privileged constructors, leading to access to the host process object. The real-world implications of this vulnerability are significant for multi-tenant environments, plugin execution systems, and any contexts where services utilize vm2 as a boundary against malicious input. This includes continuous integration, automation, and workflow platforms that may expose scripting features. A working Proof-of-Concept (PoC) is publicly available, demonstrating both the sandbox escape and host command execution capabilities. This increases the risk of operationalization of the exploit in real-world attacks, notably against services that expose untrusted input through vm2. To mitigate the risks associated with CVE-2026-26956, organizations are advised to review their codebases for instances of http://VM.run() with untrusted input, ascertain if they are utilizing Node.js 25.x, and ensure the required WebAssembly features are enabled. Upgrading beyond vm2 version 3.10.4 is also recommended to safeguard against exploitation. By focusing on detection measures, including the identification of paths where untrusted code can enter vm2, organizations can better protect themselves from this critical vulnerability.

    Post summary

    CVE‑2026‑26956 is a critical sandbox escape in vm2 that allows host RCE via WebAssembly exception handling; a PoC is publicly available, exploitation has been confirmed, and upgrading vm2 beyond 3.10.4 or disabling vulnerable WebAssembly features mitigates the risk.

    00010107
    646 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    1/4 🚨 Cyber Snapshot: May 7, 2026 Palo Alto PAN-OS zero-day (CVE-2026-0300) under active exploitation for weeks — root RCE on exposed firewalls. CISA just added it to KEV. Patch incoming May 13, but act NOW. 2/4 Cisco CVE-2026-20188 DoS hits Crosswork/NSO — unauth remote crash requiring manual reboot. No known exploits yet, but rate-limiting fail is nasty. Update ASAP. vm2 sandbox escape (CVE-2026-26956) lets attackers break out to host. PoC public. Node.js users: upgrade immediately. 3/4 Supply chain hits: DAEMON Tools installers trojanized. MuddyWater (Iran) using Chaos ransomware as decoy for espionage via Teams phishing. Backups getting destroyed pre-encryption — rethink recovery. 4/4 Immediate Actions: Restrict PAN-OS portals, patch Cisco/vm2, verify backups offline/immutable. Save this thread. Follow for daily drops. What’s your biggest exposure right now? 👇 #CyberSecurity #ZeroDay Cybersecurity Landscape Snapshot – May 07, 2026 Executive Summary The last 24 hours were dominated by a critical Palo Alto Networks PAN-OS zero-day (CVE-2026-0300) under active exploitation, promptly added to CISA’s KEV Catalog. Additional high-impact issues include a Cisco DoS vulnerability requiring manual recovery, a vm2 sandbox escape with public PoC, and ongoing supply-chain + nation-state activity. No major new ransomware claims, but backup destruction tactics remain a key theme. Organizations should prioritize firewall exposures and Node.js dependencies. 1. Supply Chain & Third-Party Vectors Disc Soft Limited (DAEMON Tools) confirmed a supply-chain attack where installers were trojanized since early April, affecting thousands globally. A clean version (Lite 12.5.1) was released. Users should download only from verified sources and scan existing installs. 2. Nation-State Activity MuddyWater (Iranian APT) deployed Chaos ransomware as a decoy to mask espionage operations. Initial access via Microsoft Teams social engineering, followed by persistence. The ransomware component complicates attribution. 3. Vulnerabilities & Patching (with KEV table)

    Post summary

    The post reports a PAN‑OS zero‑day (CVE‑2026‑0300) under active exploitation, a public PoC for a vm2 sandbox escape, and urges immediate patching and mitigation across affected systems.

    10000153
    12.4K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are exploiting CVE-2026-26956 to escape vm2 sandboxes and execute arbitrary code on host systems. The vulnerability enables privilege escalation and lateral movement across Node.js environments. Runtime segmentation helps limit blast radius when sandbox escapes occur. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/critical-vm2-sandbox-bug-cve-2026-26956

    Post summary

    Attackers are actively exploiting CVE-2026-26956 to escape vm2 sandboxes and execute arbitrary code on host systems, enabling privilege escalation and lateral movement across Node.js environments.

    0001056
    1.9K followersView on X
  • Xavier Rivera@XavierRiveraX
    PoC

    A critical sandbox escape in vm2 — Node.js's most-used JavaScript isolation library at 1.3M weekly npm downloads — lets attackers execute arbitrary code on the host. CVE-2026-26956 has a published PoC exploit, per BleepingComputer.

    Post summary

    CVE‑2026‑26956 is a sandbox escape flaw in Node.js’s vm2 that permits arbitrary host code execution and has a published PoC exploit; there is no indication of active exploitation or vendor patch.

    1000079
    267 followersView on X
  • nuno almeida@_nunoalmeida_
    PoC

    "Tracked as CVE-2026-26956 and has been confirmed to impact vm2 version 3.10.4, although earlier releases may also be vulnerable. Proof-of-concept (PoC) exploit code has been published."

    Post summary

    CVE-2026-26956 impacts vm2 3.10.4 and earlier releases; a proof‑of‑concept exploit code has been made public.

    00010205
    338 followersView on X
  • Julio Elizondo@jelizor
    PoC

    In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents

    Post summary

    Multiple high‑severity sandbox escape CVEs are highlighted with explicit proof‑of‑concept claims and detailed technical descriptions, underscoring the widespread vulnerability of AI agent sandbox implementations.

    0000070
    27 followersView on X
  • SecAlerts@SecAlertsCo
    PoC

    CVE-2026-26956 — critical 9.8. vm2 WASM sandbox escape on Node 25 only: attacker code in http://VM.run() gets full host process access, no cooperation needed. Fix: upgrade vm2 to v3.10.5. #nodejs https://secalerts.co/vulnerability/CVE-2026-26956

    Post summary

    CVE-2026-26956 is a critical 9.8 sandbox escape in vm2 that has a publicly linked PoC enabling full host access; upgrading to vm2 v3.10.5 patches the issue.

    0000082
    826 followersView on X
  • CCB Alert@CCBalert
    PoC

    Warning: Critical Sandbox Escape in #vm2. #CVE-2026-26956 CVSS: 9.8. This #0Day allows an attacker to escape the sandbox and execute arbitrary commands on the host! A #PoC is available. More info in our advisory: https://ccb.belgium.be/advisories/warning-full-sandbox-escape-nodejs-sandbox-vm2-patch-immediately #Patch #Patch #Patch

    Post summary

    The post warns of a critical sandbox escape in vm2, notes that a PoC exists, and urges immediate patching.

    00000260
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more