Vm2 Project maintains a JavaScript sandbox library that allows isolated execution of untrusted code within Node.js environments, a mechanism widely adopted in applications requiring dynamic code evaluation. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the inherent difficulty of isolating hostile code and the sandbox's direct exposure to runtime exploitation. The exposure recurs through code-injection and dynamic-code-management weakness classes—including improper code generation control and protection mechanism failures—that are structural to sandbox escape attacks and undermine the fundamental trust boundary the library is meant to establish. Defenders deploying this library should treat security advisories as urgent and re-evaluate isolation assumptions following patching. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vm2 Project over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30547CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allo | Apr 17, 2023 | 10.0 | 71 | NO | NO |
CVE-2023-29017CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareS | Apr 6, 2023 | 9.8 | 68 | NO | NO |
CVE-2022-36067CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gai | Sep 6, 2022 | 10.0 | 58 | NO | NO |
CVE-2026-26956CRITICAL vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host | May 4, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-24118CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from | May 4, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-26332CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in | May 4, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-24781CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to writ | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-24120CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-44006CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability | May 13, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-44005CRITICAL vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes i | May 13, 2026 | 10.0 | 40 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vm2 Project.
Media articles that mention a CVE ID that affects a product developed by Vm2 Project — matched by CVE ID, not by vendor name.