DFIR Lab[verified]@DFIR_LabPatch
The post warns of a critical Node.js vm2 sandbox escape (CVE-2026-44007) that allows arbitrary OS command execution when nesting is enabled, and advises instant patching to version 3.11.1 or later.
Open Source Security mailing list@oss_securityPatch
VM2 suffers a critical sandbox escape (CVE‑2026‑44007) affecting versions up to 3.11.0; the issue is fixed in 3.11.1.
iototsecnews@iototsecnewsGeneral
The article reports on 11 vm2 Node.js sandbox vulnerabilities that could lead to arbitrary code execution, outlining their causes and listing affected CVEs, but it offers no PoC, exploit, patch, or active exploitation evidence.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text references CVE-2026-44007, mentions “vm2,” and includes a link to a Vulmon page, but offers no further details about the vulnerability, PoC, exploitation, or mitigation.