CVE-2026-47140Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. This issue has been patched in version 3.11.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-05-22); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-05-22: 3Mentions · 2026-05-29: 1Mentions · 2026-06-12: 1Mentions · 2026-06-19: 1Mentions · 2026-06-29: 1Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-29: 1Technical Details · 2026-05-22: 3Technical Details · 2026-05-29: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-19: 105-2205-2906-1206-1906-29
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-223
Disclosure2Patch1
2026-05-291
Patch1
2026-06-121
Disclosure1
2026-06-191
Disclosure1
2026-06-291
General1
Full discourse7 posts
  • yousukezan@yousukezan
    Disclosure

    Node.js向けサンドボックスライブラリ「vm2」で、ホスト環境を完全突破できる重大脆弱性5件が公開された。未修正版では任意コード実行が可能になる。 影響を受けるのはvm2 3.11.3以前で、いずれもサンドボックス隔離を無効化する深刻な問題となる。最も危険なCVE-2026-47140はCVSS 10.0で、NodeVMの組み込みモジュール拒否リストに「process」と「inspector/promises」が含まれていなかった。攻撃者はrequire.builtin設定を悪用し、ホスト側プロセスや機密情報へ直接アクセスできる。 CVE-2026-47210(CVSS 9.8)はNode 26などJSPI対応環境に影響する。Promise.prototype.finally()処理の欠陥を利用し、ホスト由来のエラーオブジェクトを取得してサンドボックスを脱出できる。認証情報やデータベース情報窃取にもつながる。 さらにCVE-2026-47137では、過去の修正パッチ実装不備が悪用可能だった。requireオプション未指定時に安全確認を回避でき、内部で新たなvm2環境を生成しchild_process経由でOSコマンド実行が可能になる。 残るCVE-2026-47208とCVE-2026-47131はPromise種別処理やBuffer内部オブジェクトのプロトタイプ操作を悪用する。細工したPromiseや_lookupGetter/_lookupSetter呼び出しにより、ホスト側TypeErrorコンストラクタを取得して完全なサンドボックス脱出へ至る。 vm2はユーザー提供JavaScript実行基盤として広く利用されているが、今回の問題に設定回避策は存在しない。開発チームにはvm2 3.11.4以降への緊急更新が求められている。 https://securityonline.info/vm2-sandbox-escape-vulnerabilities-cve-2026-47140-node-rce/

    Post summary

    The piece discloses five critical sandbox escape CVEs in vm2, explains their exploitation vectors, and urges users to apply the 3.11.4 patch immediately.

    0402252.3K
    14.5K followersView on X
  • yousukezan@yousukezan
    Patch

    Node.js向けサンドボックスライブラリ「vm2」で、ホスト環境を完全突破できる重大脆弱性5件が公開された。未修正版では任意コード実行が可能になる。 影響を受けるのはvm2 3.11.3以前で、いずれもサンドボックス隔離を無効化する深刻な問題となる。最も危険なCVE-2026-47140はCVSS 10.0で、NodeVMの組み込みモジュール拒否リストに「process」と「inspector/promises」が含まれていなかった。攻撃者はrequire.builtin設定を悪用し、ホスト側プロセスや機密情報へ直接アクセスできる。 CVE-2026-47210(CVSS 9.8)はNode 26などJSPI対応環境に影響する。Promise.prototype.finally()処理の欠陥を利用し、ホスト由来のエラーオブジェクトを取得してサンドボックスを脱出できる。認証情報やデータベース情報窃取にもつながる。 さらにCVE-2026-47137では、過去の修正パッチ実装不備が悪用可能だった。requireオプション未指定時に安全確認を回避でき、内部で新たなvm2環境を生成しchild_process経由でOSコマンド実行が可能になる。 残るCVE-2026-47208とCVE-2026-47131はPromise種別処理やBuffer内部オブジェクトのプロトタイプ操作を悪用する。細工したPromiseや_lookupGetter/_lookupSetter呼び出しにより、ホスト側TypeErrorコンストラクタを取得して完全なサンドボックス脱出へ至る。 vm2はユーザー提供JavaScript実行基盤として広く利用されているが、今回の問題に設定回避策は存在しない。開発チームにはvm2 3.11.4以降への緊急更新が求められている。 https://securityonline.info/vm2-sandbox-escape-vulnerabilities-cve-2026-47140-node-rce/

    Post summary

    The article discloses five severe sandbox‑escape CVEs affecting vm2, detailing technical aspects and emphasizing the urgent need for upgrading to vm2 3.11.4 or newer.

    0101432.2K
    14.5K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Five critical sandbox escape flaws in vm2 (CVE-2026-47140 & more) allow unauthenticated remote code execution on the host server. Update now! #NodeJS #vm2 #SandboxEscape #VulnerabilityAlert #RCE #CVE202647140 #DevSecOps #AppSec #JavaScript https://securityonline.info/vm2-sandbox-escape-vulnerabilities-cve-2026-47140-node-rce/ https://t.co/6aBDyJSykZ

    Post summary

    The post announces five sandbox escape flaws in vm2 (CVE‑2026‑47140 and others) that allow unauthenticated RCE on the host, urging users to update—no exploit or PoC details are provided.

    11031592
    12.5K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVE-2026-47140 is a good patch-discipline check. Affected systems / vulnerability. Public details are enough to start scoping. What detection would tell you this moved from advisory to activity?

    Post summary

    The message references CVE‑2026‑47140 as a point for patch discipline but offers no PoC, technical detail, exploitation evidence, or patch information, making it a generic statement.

    1000033
    335 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 vm2 Sandbox: A Cluster of Perfect-10 Breakouts The Node.js vm2 sandbox library is having a catastrophic week. Four separate CVSS 10.0 vulnerabilities — CVE-2026-47208, CVE-2026-47137, CVE-2026-47140, and CVE-2026-47131 — all…

    Post summary

    The post highlights four catastrophic CVSS 10.0 vulnerabilities in Node.js vm2, lacking exploit or remediation information.

    1000027
    81 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-47140 Sandbox Bypass in vm2 NodeVM via Unrestricted Process and Inspector Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47140

    Post summary

    Brief announcement of a sandbox bypass in vm2 NodeVM via unrestricted process and inspector access; no PoC, exploit, patch, or active exploitation details are given.

    0000028
    4.0K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVSS 10 in vm2 (npm). CVE-2026-47140 is a sandbox escape - NodeVM's denylist misses `process` and `inspector/promises`, enabling full RCE. Update to v3.11.4 now. #nodejs #security https://secalerts.co/vulnerability/CVE-2026-47140 https://t.co/Dp35UPHbGi

    Post summary

    CVE-2026-47140 is a sandbox escape that enables full RCE in NodeVM; the v3.11.4 update fixes the issue.

    0000072
    826 followersView on X

Explore more