Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch vm2_project vm2 systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This allows sandboxed code to load excluded builtins like child_process and achieve remote code execution. This vulnerability is fixed in 3.11.0.
The article announces 11 critical vulnerabilities in the vm2 Node.js sandbox library, detailing their types and potential impact, but provides no PoC, exploit code, or patch information.
Status vs CVSS vs Attack Vector:
CVE-2026-24118: Patched in 3.11.0 (vs CVSS 9.8 | Attack Vector `__lookupGetter__` + Buffer.apply → host Function.prototype)
CVE-2026-43999: Patched in 3.11.0 (vs CVSS 9.9 | Attack Vector NodeVM builtin allowlist bypass (`builtin: ['*',…
Post summary
Both CVE-2026-24118 and CVE-2026-43999 have been patched in version 3.11.0, with detailed CVSS scores and attack vector information provided, but no PoC or active exploitation is mentioned.
In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days.
vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility.
Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score.
PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent.
n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable.
NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure.
The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence.
If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9.
#TheAgentProblem#AISecurity#Agents
Post summary
A series of newly disclosed, high‑severity CVEs affecting multiple AI sandbox implementations; each includes public PoCs, detailed technical exploitation vectors, and no available patches.