HarborGuard / CVE
Back to search
CRITICALCVE-2026-44006Published Modified CNA GitHub_M

CVE-2026-44006: vm2: Sandbox Escape

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

Metrics

CVSS v3.1
10.0
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • patriksimek / vm2
    < 3.11.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-44006: vm2: Sandbox Escape | HarborGuard CVE