CVE-2026-47698Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2Exploit Tool / Code · 2026-08-18: 1Patch / Workaround · 2026-08-18: 2Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Aikido Community Japan@AikidoCommJP
    Patch

    vm2、また問題です。 本来は隔離されているJavaScriptが、そのセキュリティ境界を破って、サーバー側まで到達できてしまう脆弱性が見つかりました。 CVE-2026-47698。 対象は 0.0.1〜3.11.5。3.11.6で修正されています。 ただ、今回のCVEだけを見るより、そもそもvm2が何なのかを見た方が面白い。 vm2は、Node.jsの中で「外から渡されたJavaScript」を隔離して実行するためのモジュールです。 たとえば、 ・ワークフローの途中でユーザーがJavaScriptを書く ・ローコード製品で独自の式や処理を書く ・プラグインやカスタムコードを実行する ・最近なら、AIエージェントやLLMが生成したコードを実行する そんな場所で使われます。 別の仮想マシンやコンテナを立てるのではなく、同じNode.jsプロセスの中でコードを隔離して動かせる。 軽い。速い。組み込みやすい。 だから広がりました。 ところが、このvm2。 2023年に一度、メンテナンス終了が宣言されています。 理由は単なる人手不足ではありません。 サンドボックスのセキュリティ境界を破られる問題が相次ぎ、安全に維持するのが難しいとして終了した。 代替として isolated-vm への移行まで勧められました。 普通なら、ここで終わったOSSです。 でも終わらなかった。 利用する製品やサービスが多く、今でも週100万回近くダウンロードされている。 そして2025年、元のオーナーが開発を再開しました。 ただし、復活したからといって、根本の構造が別物になったわけではありません。 2026年に入ってからも問題は続いています。 1月には CVE-2026-22709。 5月の3.11.0では、13件のSecurity Advisoryに対応。 そして8月、またvm2です。 今回の3.11.6では、さらに5件のSecurity Advisoryに対応。 その一つが、昨日のAikido Intelにも上がってきた CVE-2026-47698 です。 しかも、このCVE番号自体は5月に予約されていました。 5月に大量の問題を修正して終わったわけではない。 その後も調査と修正が続き、3か月後にまた新しい問題が表に出てきた。 気になるのは、個々のCVEより、この流れです。 一度は「安全に維持するのが難しい」として終了した。 需要が消えず、復活した。 そして復活後も、セキュリティ境界を破られる問題が続いている。 さらに今は、昔より「外から来たコードを実行する」場面が増えています。 AIがコードを書くようになったからです。 「うちはvm2なんて使っていない」と思っていても、自分でnpm installしたとは限りません。 ワークフロー製品、ローコード、プラグイン、コード実行機能。 その内側に入っている可能性があります。 確認したいのは、 自社のサービスで、ユーザーやAIが作ったJavaScriptを実行できる場所はどこか。 その下で、何を使って隔離しているのか。 AI時代になって新しい問題が突然生まれたというより、 昔から難しかった「信頼できないコードを、どこまで安全に実行できるのか」という問題が、急に重要になってきたように見えます。 https://github.com/patriksimek/vm2/releases/tag/3.11.6 #vm2 #脆弱性 #AppSec #AIセキュリティ #サンドボックス #NodeJS #AikidoIntel

    Post summary

    The post reports a sandbox escape vulnerability in vm2 (CVE‑2026‑47698), notes it was fixed in version 3.11.6, and discusses ongoing issues with the module across products.

    10010467
    830 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - vm2 sandbox escape → host RCE, plus alloc-limit DoS (CVE-2026-47698, CVE-2026-47686, GHSA-m5w8-4gq2-6f8x, CVE-2026-47683, GHSA-v836-6xw4-9cx3) Five flaws in vm2 < 3.11.6. Escape → host RCE: the proto-mutator fix is bypassable via http://indirectcall.call(indirectcall, dangerousmutator, ...); handleException() doesn't sanitize Error.cause, leaking host objects like process; DANGEROUS_BUILTINS omits os/dns, so builtin: ['*'] allows a process-wide DNS hijack. DoS: bufferAllocLimit bypassable via Buffer.concat and TypedArray constructors. 👉Affected: vm2 (npm) ≤ 3.11.5 | Upgrade to 3.11.6

    Post summary

    The post announces critical vm2 sandbox escape flaws with detailed exploitation methods and recommends upgrading to v3.11.6.

    0000089
    291 followersView on X

Explore more