CVE-2026-43997Patch(vm2_project / vm2)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vm2_project vm2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-653

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
vm2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-06-12: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-12: 105-1406-12
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-05-141
Patch1
2026-06-121
Disclosure1
Full discourse2 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-43997. vm2 Access to Host Object Enables Sandbox Escape Inventory first. Panic never helps.

    Post summary

    The advisory announces a sandbox‑escape vulnerability in vm2 (CVE-2026‑43997), but provides no proof‑of‑concept, exploit, active usage evidence, or patch details.

    1000025
    334 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    5 Critical CVEs to Fix Now - vm2 sandbox Affected: vm2; Fleet Helm deployer; ERPNext Internet-facing risks dominate, led by sandbox escapes in Node.js vm2 and exposure through automation tooling. • CVE-2026-43997 (CVSS 10.0) iControl REST vulnerability allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that allow running arbitrary commands. Affected versions: unspecified. • CVE-2026-44005 (CVSS 10.0) vm2's bridge exposes mutable proxies for host-realm intrinsic prototypes and forwards sandbox writes into the underlying host objects, enabling host compromise; fixed in 3.11.0. Affected versions: 3.9.6-3.10.5. • CVE-2026-44006 (CVSS 10.0) vm2 prior to 3.11.0 allows reaching BaseHandler.getPrototypeOf to obtain arbitrary prototypes, enabling host access and command execution. Affected versions: <3.11.0. • CVE-2026-41050 (CVSS 9.9) Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to read secrets from any namespace on every downstream cluster targeted by their GitRepo. Affected versions: unspecified. • CVE-2026-44442 (CVSS 9.9) ERPNext before 16.9.1 fails to enforce proper authorization checks, allowing data modification beyond the holder’s permitted role. Affected versions: before 16.9.1. 🛠️ Action • Patch vm2 to the fixed 3.11.x series (≥3.11.0, ideally 3.11.2+); upgrade ERPNext to 16.9.1 or later; apply vendor advisories for Fleet Helm deployer. • Prioritize internet-facing instances and edge appliances for remediation first. • If a fix is not available yet, apply mitigations: restrict exposure, disable risky features, rotate credentials where applicable. • Add detections for exploitation patterns: sandbox escapes, host-prototype mutations, unauthorized API/config changes, and unusual process spawns. • Hunt for indicators in logs, EDR, WAF related to the affected services during the disclosure window. • Validate remediation with version checks and configuration verification, and monitor for reversion or new indicators.

    Post summary

    The advisory highlights five critical CVEs affecting vm2, Fleet Helm deployer, and ERPNext, provides technical details and CVSS scores, and offers concrete patch and mitigation instructions to remediate the high-risk vulnerabilities.

    0001050
    545 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more