CVE-2026-43999Disclosure(vm2_project / vm2)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This allows sandboxed code to load excluded builtins like child_process and achieve remote code execution. This vulnerability is fixed in 3.11.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-14); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
vm2

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-14: 2Mentions · 2026-05-26: 1Mentions · 2026-06-10: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-05-26: 1Patch / Workaround · 2026-06-10: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-10: 105-1405-2606-1008-27
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-142
Disclosure1General1
2026-05-261
Disclosure1
2026-06-101
Patch1
2026-08-271
General1
Full discourse5 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The text is a simple enumeration of CVE identifiers without any additional information.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The message merely lists CVE identifiers with no additional context or supporting information.

    30124138.4K
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    vm2 Node.js Sandbox ライブラリの 11 件の脆弱性:任意のコード実行などの可能性 https://iototsecnews.jp/2026/05/07/critical-vm2-node-js-library-flaws-enable-arbitrary-code-execution-attacks/ 今回の脆弱性群の主な原因は、サンドボックスとホストを繋ぐブリッジ機構において、オブジェクト参照の管理が不完全だったことにあります。 CVE-2026-26956 のように JavaScript 内部の例外処理の悪用を許すものや、 CVE-2026-43999 のように設定上のロジック不備を露呈するものにより、本来は隔離されるべきホスト側の機能へのアクセスが可能になっています。 また CVE-2026-44007 のように、特定の条件下でライブラリ自身がサンドボックス内に注入されてしまう設計上の課題も指摘されています。 CVE-2026-44008 や CVE-2026-44009 など未修正の問題も残っており、言語仕様の深層を防御することの難しさが浮き彫りにされています。ご利用のチームは、ご注意ください。 #CVE202624118 #CVE202624120 #CVE202624781 #CVE202626332 #CVE202626956 #CVE202643997 #CVE202643999 #CVE202644005 #CVE202644006 #CVE202644007 #CVE202644008 #CVE202644009 #Nodejs #vm2 #Vulnerability

    Post summary

    The article announces 11 critical vulnerabilities in the vm2 Node.js sandbox library, detailing their types and potential impact, but provides no PoC, exploit code, or patch information.

    01001144
    491 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Status vs CVSS vs Attack Vector: CVE-2026-24118: Patched in 3.11.0 (vs CVSS 9.8 | Attack Vector `__lookupGetter__` + Buffer.apply → host Function.prototype) CVE-2026-43999: Patched in 3.11.0 (vs CVSS 9.9 | Attack Vector NodeVM builtin allowlist bypass (`builtin: ['*',…

    Post summary

    Both CVE-2026-24118 and CVE-2026-43999 have been patched in version 3.11.0, with detailed CVSS scores and attack vector information provided, but no PoC or active exploitation is mentioned.

    1000038
    258 followersView on X
  • Julio Elizondo@jelizor
    Disclosure

    In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents

    Post summary

    A series of newly disclosed, high‑severity CVEs affecting multiple AI sandbox implementations; each includes public PoCs, detailed technical exploitation vectors, and no available patches.

    0000070
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more