CVE-2026-47135General

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — verified with a full util.promisify hijack chain. This issue has been patched in version 3.11.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-19: 1Mentions · 2026-06-12: 105-1906-12
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • 秋风@q1uf3ng
    General

    vm2 cve*3 1 Critical10/ 10 2 high CVE-2026-47137 CVE-2026-47209 CVE-2026-47135 https://t.co/mVLkWf7QCs

    Post summary

    The text merely lists three CVE identifiers with minimal context, lacking any technical or actionable information.

    03054226.8K
    2.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-47135 Sandbox Escape in vm2 via Cross-Realm Symbol Manipulation Before 3.11.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47135

    Post summary

    The text merely announces the CVE and provides a link for more information, without describing any exploitation, PoC, patch, or technical specifics.

    0000031
    4.0K followersView on X

Explore more