CVE-2026-47210Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). In the tested configuration, a JSPI-backed Promise can reach Promise.prototype.finally() in a way that bypasses the expected Promise-species hardening and exposes a host-originated rejection object to attacker-controlled species logic, breaking the sandbox boundary. This issue has been patched in version 3.11.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-22); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-22: 2Mentions · 2026-06-12: 1Mentions · 2026-06-13: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-05-22: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 105-2206-1206-13
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-222
Disclosure2
2026-06-121
Patch1
2026-06-131
Patch1
Full discourse4 posts
  • yousukezan@yousukezan
    Disclosure

    Node.js向けサンドボックスライブラリ「vm2」で、ホスト環境を完全突破できる重大脆弱性5件が公開された。未修正版では任意コード実行が可能になる。 影響を受けるのはvm2 3.11.3以前で、いずれもサンドボックス隔離を無効化する深刻な問題となる。最も危険なCVE-2026-47140はCVSS 10.0で、NodeVMの組み込みモジュール拒否リストに「process」と「inspector/promises」が含まれていなかった。攻撃者はrequire.builtin設定を悪用し、ホスト側プロセスや機密情報へ直接アクセスできる。 CVE-2026-47210(CVSS 9.8)はNode 26などJSPI対応環境に影響する。Promise.prototype.finally()処理の欠陥を利用し、ホスト由来のエラーオブジェクトを取得してサンドボックスを脱出できる。認証情報やデータベース情報窃取にもつながる。 さらにCVE-2026-47137では、過去の修正パッチ実装不備が悪用可能だった。requireオプション未指定時に安全確認を回避でき、内部で新たなvm2環境を生成しchild_process経由でOSコマンド実行が可能になる。 残るCVE-2026-47208とCVE-2026-47131はPromise種別処理やBuffer内部オブジェクトのプロトタイプ操作を悪用する。細工したPromiseや_lookupGetter/_lookupSetter呼び出しにより、ホスト側TypeErrorコンストラクタを取得して完全なサンドボックス脱出へ至る。 vm2はユーザー提供JavaScript実行基盤として広く利用されているが、今回の問題に設定回避策は存在しない。開発チームにはvm2 3.11.4以降への緊急更新が求められている。 https://securityonline.info/vm2-sandbox-escape-vulnerabilities-cve-2026-47140-node-rce/

    Post summary

    Five critical vm2 sandbox escape vulnerabilities (CVE‑2026‑47140, 47137, 47208, 47131, 47210) have been disclosed with detailed technical paths and CVSS scores, and an urgent update to vm2 3.11.4 is recommended.

    0402252.3K
    14.5K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Node.js向けサンドボックスライブラリ「vm2」で、ホスト環境を完全突破できる重大脆弱性5件が公開された。未修正版では任意コード実行が可能になる。 影響を受けるのはvm2 3.11.3以前で、いずれもサンドボックス隔離を無効化する深刻な問題となる。最も危険なCVE-2026-47140はCVSS 10.0で、NodeVMの組み込みモジュール拒否リストに「process」と「inspector/promises」が含まれていなかった。攻撃者はrequire.builtin設定を悪用し、ホスト側プロセスや機密情報へ直接アクセスできる。 CVE-2026-47210(CVSS 9.8)はNode 26などJSPI対応環境に影響する。Promise.prototype.finally()処理の欠陥を利用し、ホスト由来のエラーオブジェクトを取得してサンドボックスを脱出できる。認証情報やデータベース情報窃取にもつながる。 さらにCVE-2026-47137では、過去の修正パッチ実装不備が悪用可能だった。requireオプション未指定時に安全確認を回避でき、内部で新たなvm2環境を生成しchild_process経由でOSコマンド実行が可能になる。 残るCVE-2026-47208とCVE-2026-47131はPromise種別処理やBuffer内部オブジェクトのプロトタイプ操作を悪用する。細工したPromiseや_lookupGetter/_lookupSetter呼び出しにより、ホスト側TypeErrorコンストラクタを取得して完全なサンドボックス脱出へ至る。 vm2はユーザー提供JavaScript実行基盤として広く利用されているが、今回の問題に設定回避策は存在しない。開発チームにはvm2 3.11.4以降への緊急更新が求められている。 https://securityonline.info/vm2-sandbox-escape-vulnerabilities-cve-2026-47140-node-rce/

    Post summary

    The article discloses five critical sandbox escape vulnerabilities in vm2, provides technical details and CVSS scores, and urges users to update to version 3.11.4 or later to mitigate the risks.

    0101432.2K
    14.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-47210 (CVSS 9.8) - vm2 Node.js sandbox escape allows arbitrary code execution on host when using WebAssembly JSPI with async. Affects versions <3.11.4. Patch immediately! #CVE #PatchNow #ThreatIntel https://t.co/nt672ljtf5

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑47210) in vm2 Node.js with a CVSS of 9.8, warns that it allows arbitrary code execution, and urges immediate patching.

    0000032
    44 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-47210 Sandbox Escape Vulnerability in vm2 Prior to Version 3.11.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47210

    Post summary

    The note flags CVE‑2026‑47210 as a sandbox escape flaw in vm2 that was remedied by version 3.11.4, but offers no PoC or exploit details.

    0000032
    4.0K followersView on X

Explore more