Vm2

Vendor:

First CVE: Oct 18, 2021 · Active for 4 years

32
Total CVEs
More Total CVEs than 96% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
9.3
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vm2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2021
4 years ago
Most Recent CVE
May 13, 2026
73 days ago

CVE Severity & Scoring

Vm232 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (96.9%)
High1 (3.1%)
Unknown0 (0.0%)
User Interaction
None32 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (9.4%)
High0 (0.0%)
None29 (90.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allo
Apr 17, 202310.071NONO
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareS
Apr 6, 20239.868NONO
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gai
Sep 6, 202210.058NONO
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host
May 4, 20269.845NONO
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from
May 4, 20269.843NONO
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in
May 4, 202610.042NONO
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to writ
May 4, 20269.842NONO
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can
May 4, 20269.842NONO
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability
May 13, 202610.041NONO
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes i
May 13, 202610.040NONO

Exploit Exposure

Signals from CVEs in this product scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (32 CVEs).

Media Mentions

Signals from CVEs in this product scope (32 CVEs).

Top CNAs Publishing CVEs For Vm2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.10.518.50.7%00