CVE-2026-44009Disclosure(vm2_project / vm2)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668CWE-653

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
vm2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-14: 1Technical Details · 2026-05-14: 105-0805-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • iototsecnews@iototsecnews
    Disclosure

    vm2 Node.js Sandbox ライブラリの 11 件の脆弱性:任意のコード実行などの可能性 https://iototsecnews.jp/2026/05/07/critical-vm2-node-js-library-flaws-enable-arbitrary-code-execution-attacks/ 今回の脆弱性群の主な原因は、サンドボックスとホストを繋ぐブリッジ機構において、オブジェクト参照の管理が不完全だったことにあります。 CVE-2026-26956 のように JavaScript 内部の例外処理の悪用を許すものや、 CVE-2026-43999 のように設定上のロジック不備を露呈するものにより、本来は隔離されるべきホスト側の機能へのアクセスが可能になっています。 また CVE-2026-44007 のように、特定の条件下でライブラリ自身がサンドボックス内に注入されてしまう設計上の課題も指摘されています。 CVE-2026-44008 や CVE-2026-44009 など未修正の問題も残っており、言語仕様の深層を防御することの難しさが浮き彫りにされています。ご利用のチームは、ご注意ください。 #CVE202624118 #CVE202624120 #CVE202624781 #CVE202626332 #CVE202626956 #CVE202643997 #CVE202643999 #CVE202644005 #CVE202644006 #CVE202644007 #CVE202644008 #CVE202644009 #Nodejs #vm2 #Vulnerability

    Post summary

    The post announces and explains eleven CVE vulnerabilities in the vm2 Node.js sandbox library, highlighting how improper bridge handling allows arbitrary code execution, but offers no PoC, exploit code, evidence of active exploitation, or patch information.

    01001144
    491 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 VM2, Sandbox Breakout Vulnerability, #CVE-2026-44009 (Critical) https://dailycve.com/vm2-sandbox-breakout-vulnerability-cve-2026-44009-critical/

    Post summary

    The post announces a new critical CVE (CVE-2026-44009) for VM2’s sandbox breakout but offers no additional technical details, PoC, patches, or exploitation evidence.

    0000034
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more