CVE-2026-45411Patch(vm2_project / vm2)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vm2_project vm2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668CWE-237

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
vm2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-26: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-26: 105-1405-26
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Classification over time
DateTotalLabels
2026-05-141
Patch1
2026-05-261
PoC1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - vm2 Sandbox Escape → Remote Code Execution (CVE-2026-45411) A sandbox escape in vm2 lets attacker-supplied code break out of the VM2 isolation and execute arbitrary commands on the host. The flaw abuses async generator behavior — when a generator closes via return, exceptions thrown during promise resolution can be caught and pivoted to host resources, bypassing every isolation guarantee vm2 advertises (CVSS 9.8, no auth, no UI). 👉 Affected: vm2 (npm) ≤ 3.11.2 | Upgrade to 3.11.3 — or migrate to isolated-vm (vm2 is deprecated)

    Post summary

    CVE‑2026‑45411 is a critical sandbox escape in vm2 enabling remote code execution; users are advised to upgrade to 3.11.3 or switch to isolated‑vm to mitigate the risk.

    00010134
    187 followersView on X
  • Julio Elizondo@jelizor
    PoC

    In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents

    Post summary

    The post highlights seven critical sandbox CVEs with public proofs of concept, detailed technical data, but no evidence of active exploitation or patches.

    0000070
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvm2_projectvm2-node.js-

Explore more