Vm2
Vendor:
First CVE: Oct 18, 2021 · Active for 4 years
32
Total CVEs
More Total CVEs than 96% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
9.3
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vm2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2021
4 years ago
Most Recent CVE
May 13, 2026
73 days ago
CVE Severity & Scoring
Vm232 CVEs
9%
16%
75%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (96.9%)
High1 (3.1%)
Unknown0 (0.0%)
User Interaction
None32 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (9.4%)
High0 (0.0%)
None29 (90.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30547CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allo | Apr 17, 2023 | 10.0 | 71 | NO | NO |
CVE-2023-29017CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareS | Apr 6, 2023 | 9.8 | 68 | NO | NO |
CVE-2022-36067CRITICAL vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gai | Sep 6, 2022 | 10.0 | 58 | NO | NO |
CVE-2026-26956CRITICAL vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host | May 4, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-24118CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from | May 4, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-26332CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in | May 4, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-24781CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to writ | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-24120CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-44006CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability | May 13, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-44005CRITICAL vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes i | May 13, 2026 | 10.0 | 40 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Vm2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.10.5 | 1 | 8.5 | 0.7% | 0 | 0 |