CVE-2026-44007Patch(vm2_project / vm2)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vm2_project vm2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host. Any application that runs untrusted code inside a NodeVM with nesting: true is fully compromised. This vulnerability is fixed in 3.11.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-1100

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-05); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
vm2

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-14: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-28: 105-0505-0605-1405-28
Signal classification2 categories
Patch
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-051
Patch1
2026-05-061
General1
2026-05-141
General1
2026-05-281
Patch1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-44007: vm2: sandbox escape in NodeVM with nesting:true https://www.openwall.com/lists/oss-security/2026/05/05/11 Affected versions: <= 3.11.0 Fixed version: 3.11.1 Severity: Critical vm2 attempts to sandbox untrusted JavaScript code within the same Node.js process as your application

    Post summary

    VM2 suffers a critical sandbox escape (CVE‑2026‑44007) affecting versions up to 3.11.0; the issue is fixed in 3.11.1.

    01053626
    4.7K followersView on X
  • iototsecnews@iototsecnews
    General

    vm2 Node.js Sandbox ライブラリの 11 件の脆弱性:任意のコード実行などの可能性 https://iototsecnews.jp/2026/05/07/critical-vm2-node-js-library-flaws-enable-arbitrary-code-execution-attacks/ 今回の脆弱性群の主な原因は、サンドボックスとホストを繋ぐブリッジ機構において、オブジェクト参照の管理が不完全だったことにあります。 CVE-2026-26956 のように JavaScript 内部の例外処理の悪用を許すものや、 CVE-2026-43999 のように設定上のロジック不備を露呈するものにより、本来は隔離されるべきホスト側の機能へのアクセスが可能になっています。 また CVE-2026-44007 のように、特定の条件下でライブラリ自身がサンドボックス内に注入されてしまう設計上の課題も指摘されています。 CVE-2026-44008 や CVE-2026-44009 など未修正の問題も残っており、言語仕様の深層を防御することの難しさが浮き彫りにされています。ご利用のチームは、ご注意ください。 #CVE202624118 #CVE202624120 #CVE202624781 #CVE202626332 #CVE202626956 #CVE202643997 #CVE202643999 #CVE202644005 #CVE202644006 #CVE202644007 #CVE202644008 #CVE202644009 #Nodejs #vm2 #Vulnerability

    Post summary

    The article reports on 11 vm2 Node.js sandbox vulnerabilities that could lead to arbitrary code execution, outlining their causes and listing affected CVEs, but it offers no PoC, exploit, patch, or active exploitation evidence.

    01001144
    491 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-44007 | CVSS 9.1 vm2 sandbox escape in Node.js allows arbitrary OS command execution when nesting:true is enabled. Affects versions <3.11.1. ✅ Patch immediately to 3.11.1+ #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/DQTIFtdLYD

    Post summary

    The post warns of a critical Node.js vm2 sandbox escape (CVE-2026-44007) that allows arbitrary OS command execution when nesting is enabled, and advises instant patching to version 3.11.1 or later.

    0000039
    30 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44007 vm2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44007

    Post summary

    The text references CVE-2026-44007, mentions “vm2,” and includes a link to a Vulmon page, but offers no further details about the vulnerability, PoC, exploitation, or mitigation.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more