Critical vm2 Vulnerability Allows Arbitrary Code Execution on Host Systems

Critical vm2 Vulnerability Allows Arbitrary Code Execution on Host Systems

First seen 7 May 2026, 11:13 UTC BleepingcomputerThehackernewsCybersecuritynewsHeise.Dewww.npmjs.com+4 85% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-26956) in the vm2 Node.js sandboxing library enables attackers to escape the sandbox and execute arbitrary code on host systems. This flaw affects vm2 version 3.10.4 and earlier, particularly in environments running Node.js 25 with WebAssembly exception handling enabled. The vulnerability arises from improper handling of exceptions crossing between the sandbox and the host, allowing attackers to access sensitive Node.js internals. Users are urged to upgrade to vm2 version 3.10.5 or later to mitigate risks. This incident is part of a series of vulnerabilities affecting vm2, highlighting ongoing challenges in securely isolating untrusted code. The library is widely used, with over 1.3 million weekly downloads, impacting numerous applications relying on it for executing user-supplied scripts.

Key Points: • CVE-2026-26956 allows arbitrary code execution on host systems running vulnerable vm2 versions. • The vulnerability affects environments with Node.js 25 and WebAssembly exception handling enabled. • Users should upgrade to vm2 version 3.10.5 or later to mitigate exploitation risks.

ThreatCluster AI

Timeline

2022-09-06
CVE-2022-36067 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-06
CVE-2023-29017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-17
CVE-2023-30547 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-26
CVE-2026-22709 published
A critical sandbox escape flaw in vm2 was disclosed, allowing arbitrary code execution.
Bleepingcomputer
2026-05-04
CVE-2026-26956 published
A new critical vulnerability in vm2 was published, enabling code execution on the host system.
Bleepingcomputer
2026-05-06
PoC exploit code published
Proof-of-concept exploit code for CVE-2026-26956 was made public, demonstrating the vulnerability.
Bleepingcomputer
2026-05-07
Security advisory issued
Users are advised to upgrade to vm2 version 3.10.5 or later to mitigate exploitation risks.
Bleepingcomputer

Community

Browse all →