CVE-2026-47137Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security guard is skipped. Immediately after (line 280), the destructuring default require: requireOpts = false assigns requireOpts = false, producing the exact configuration the patch was designed to prevent. This issue has been patched in version 3.11.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-19: 1Mentions · 2026-05-30: 1Mentions · 2026-06-12: 1Mentions · 2026-06-19: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-19: 105-1905-3006-1206-19
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-191
General1
2026-05-301
Disclosure1
2026-06-121
Disclosure1
2026-06-191
Disclosure1
Full discourse4 posts
  • 秋风@q1uf3ng
    General

    vm2 cve*3 1 Critical10/ 10 2 high CVE-2026-47137 CVE-2026-47209 CVE-2026-47135 https://t.co/mVLkWf7QCs

    Post summary

    The tweet lists three CVE numbers and severity ratings but offers no detailed information, exploit code, or mitigation advice.

    03054226.8K
    2.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 vm2 Sandbox: A Cluster of Perfect-10 Breakouts The Node.js vm2 sandbox library is having a catastrophic week. Four separate CVSS 10.0 vulnerabilities — CVE-2026-47208, CVE-2026-47137, CVE-2026-47140, and CVE-2026-47131 — all…

    Post summary

    The excerpt announces four critical (CVSS 10.0) vulnerabilities in the Node.js vm2 sandbox library, but does not provide PoC, exploit code, or patch information.

    1000027
    81 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-47137 Sandbox Bypass in vm2 via Incomplete Security Check in NodeVM Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47137

    Post summary

    The text merely announces CVE-2026-47137 with a one‑line description of a sandbox bypass in vm2, without providing any PoC, exploit details, patch information, or evidence of active exploitation.

    0000030
    4.0K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVSS 10.0 in vm2 (npm). CVE-2026-47137 is a sandbox escape that bypasses the fix for CVE-2023-37903 - unauthenticated, no interaction needed, full compromise possible. If vm2 is in your stack, treat this as critical. #nodejs #security https://secalerts.co/vulnerability/CVE-2026-47137 https://t.co/y3riLEpaSZ

    Post summary

    A new CVE‑2026‑47137 sandbox escape affecting vm2 with CVSS 10.0 is disclosed, posing an unauthenticated, interaction‑free full compromise risk, but no PoC, exploit, or patch information is provided.

    0000091
    826 followersView on X

Explore more