PoC
#threatreport #LowCompleteness
CVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25 | 07-05-2026
Source: https://socradar.io/blog/cve-2026-26956-vm2-sandbox-escape-rce-node-js-25/
Key details below ↓
🎯Victims: Plugin execution systems, Continuous integration platforms, Automation platforms, Workflow platforms, Services running untrusted javascript
🔓CVEs: CVE-2026-26956 \[[Vulners](https://vulners.com/cve/CVE-2026-26956)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: Unknown
📚TTPs:
⚔️Tactics: 2
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1059.007
🧨IOCs:
- File: 3
💽Software: Node.js, Linux
🔠Functions: Symbol
📜Programming Languages: javascript
💻Platforms: x64
#threatreport:
CVE-2026-26956 is a critical vulnerability in the vm2 library, which is used for sandboxing untrusted JavaScript code in Node.js applications. This issue allows an attacker to escape the sandbox environment provided by vm2 version 3.10.4 and gain arbitrary code execution (RCE) in the host Node.js process, which has been assigned a CVSS score of 9.8, indicating its severity.
The vulnerability specifically affects Node.js version 25, with confirmed exploitation on Node.js v25.6.1 running on x64 Linux. Attackers exploit this vulnerability through a manipulation of WebAssembly exception handling. Vm2 primarily relies on JavaScript-level controls for sandboxing and error handling, but CVE-2026-26956 bypasses these protections utilizing a WebAssembly construct known as try_table in conjunction with a JSTag catch handler. This allows attackers to intercept JavaScript exceptions at a level that circumvents vm2's typical error management processes. Ultimately, they can use the resulting error object to access privileged constructors, leading to access to the host process object.
The real-world implications of this vulnerability are significant for multi-tenant environments, plugin execution systems, and any contexts where services utilize vm2 as a boundary against malicious input. This includes continuous integration, automation, and workflow platforms that may expose scripting features.
A working Proof-of-Concept (PoC) is publicly available, demonstrating both the sandbox escape and host command execution capabilities. This increases the risk of operationalization of the exploit in real-world attacks, notably against services that expose untrusted input through vm2.
To mitigate the risks associated with CVE-2026-26956, organizations are advised to review their codebases for instances of http://VM.run() with untrusted input, ascertain if they are utilizing Node.js 25.x, and ensure the required WebAssembly features are enabled. Upgrading beyond vm2 version 3.10.4 is also recommended to safeguard against exploitation. By focusing on detection measures, including the identification of paths where untrusted code can enter vm2, organizations can better protect themselves from this critical vulnerability.
Post summary
CVE‑2026‑26956 is a critical sandbox escape in vm2 that allows host RCE via WebAssembly exception handling; a PoC is publicly available, exploitation has been confirmed, and upgrading vm2 beyond 3.10.4 or disabling vulnerable WebAssembly features mitigates the risk.