
vm2 cve*3 1 Critical10/ 10 2 high CVE-2026-47137 CVE-2026-47209 CVE-2026-47135 https://t.co/mVLkWf7QCs
Post summary
The tweet lists three CVE numbers and severity ratings but offers no detailed information, exploit code, or mitigation advice.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default require: requireOpts = false assigns requireOpts = false, producing the exact configuration the patch was designed to prevent. This issue has been patched in version 3.11.4.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-05-19 | 1 | General1 |
| 2026-05-30 | 1 | Disclosure1 |
| 2026-06-12 | 1 | Disclosure1 |
| 2026-06-19 | 1 | Disclosure1 |

vm2 cve*3 1 Critical10/ 10 2 high CVE-2026-47137 CVE-2026-47209 CVE-2026-47135 https://t.co/mVLkWf7QCs
Post summary
The tweet lists three CVE numbers and severity ratings but offers no detailed information, exploit code, or mitigation advice.

🧨 vm2 Sandbox: A Cluster of Perfect-10 Breakouts The Node.js vm2 sandbox library is having a catastrophic week. Four separate CVSS 10.0 vulnerabilities — CVE-2026-47208, CVE-2026-47137, CVE-2026-47140, and CVE-2026-47131 — all…
Post summary
The excerpt announces four critical (CVSS 10.0) vulnerabilities in the Node.js vm2 sandbox library, but does not provide PoC, exploit code, or patch information.

CVE-2026-47137 Sandbox Bypass in vm2 via Incomplete Security Check in NodeVM Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47137
Post summary
The text merely announces CVE-2026-47137 with a one‑line description of a sandbox bypass in vm2, without providing any PoC, exploit details, patch information, or evidence of active exploitation.

CVSS 10.0 in vm2 (npm). CVE-2026-47137 is a sandbox escape that bypasses the fix for CVE-2023-37903 - unauthenticated, no interaction needed, full compromise possible. If vm2 is in your stack, treat this as critical. #nodejs #security https://secalerts.co/vulnerability/CVE-2026-47137 https://t.co/y3riLEpaSZ
Post summary
A new CVE‑2026‑47137 sandbox escape affecting vm2 with CVSS 10.0 is disclosed, posing an unauthenticated, interaction‑free full compromise risk, but no PoC, exploit, or patch information is provided.