Signal is active with 1 mentions in latest observed window
Immediate actions
Patch vm2_project vm2 systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM mutate shared host Object.prototype, Array.prototype, and Function.prototype from inside the sandbox This vulnerability is fixed in 3.11.0.
5 Critical CVEs to Fix Now - vm2 sandbox
Affected: vm2; Fleet Helm deployer; ERPNext
Internet-facing risks dominate, led by sandbox escapes in Node.js vm2 and exposure through automation tooling.
• CVE-2026-43997 (CVSS 10.0) iControl REST vulnerability allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that allow running arbitrary commands. Affected versions: unspecified.
• CVE-2026-44005 (CVSS 10.0) vm2's bridge exposes mutable proxies for host-realm intrinsic prototypes and forwards sandbox writes into the underlying host objects, enabling host compromise; fixed in 3.11.0. Affected versions: 3.9.6-3.10.5.
• CVE-2026-44006 (CVSS 10.0) vm2 prior to 3.11.0 allows reaching BaseHandler.getPrototypeOf to obtain arbitrary prototypes, enabling host access and command execution. Affected versions: <3.11.0.
• CVE-2026-41050 (CVSS 9.9) Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to read secrets from any namespace on every downstream cluster targeted by their GitRepo. Affected versions: unspecified.
• CVE-2026-44442 (CVSS 9.9) ERPNext before 16.9.1 fails to enforce proper authorization checks, allowing data modification beyond the holder’s permitted role. Affected versions: before 16.9.1.
🛠️ Action
• Patch vm2 to the fixed 3.11.x series (≥3.11.0, ideally 3.11.2+); upgrade ERPNext to 16.9.1 or later; apply vendor advisories for Fleet Helm deployer.
• Prioritize internet-facing instances and edge appliances for remediation first.
• If a fix is not available yet, apply mitigations: restrict exposure, disable risky features, rotate credentials where applicable.
• Add detections for exploitation patterns: sandbox escapes, host-prototype mutations, unauthorized API/config changes, and unusual process spawns.
• Hunt for indicators in logs, EDR, WAF related to the affected services during the disclosure window.
• Validate remediation with version checks and configuration verification, and monitor for reversion or new indicators.
Post summary
This advisory details five critical CVEs across vm2, Fleet Helm, and ERPNext, providing CVSS scores, technical description, and clear patch recommendations.