patriksimek vm2
37 known vulnerabilities in patriksimek vm2, 23 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100723 CVSS 6.9 medium vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to…
- CVE-2026-100722 CVSS 8.9 high vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply…
- CVE-2026-100721 CVSS 9.5 critical vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external`…
- CVE-2026-93606 CVSS 10.0 critical vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a…
- CVE-2026-93605 CVSS 10.0 critical vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite…
- CVE-2026-93604 CVSS 6.9 medium vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto…
- CVE-2026-93603 CVSS 10.0 critical vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js)…
- CVE-2026-92963 CVSS 6.9 medium vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable…
- CVE-2026-92962 CVSS 2.1 low vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace…
- CVE-2026-92961 CVSS 8.7 high vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to…
- CVE-2026-92960 CVSS 10.0 critical vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read…
- CVE-2026-92959 CVSS 7.1 high vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with…
- CVE-2026-92958 CVSS 8.4 high vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative…
- CVE-2026-92957 CVSS 9.4 critical vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a…
- CVE-2026-92956 CVSS 10.0 critical vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26…
- CVE-2026-92955 CVSS 10.0 critical vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter…
- CVE-2026-92954 CVSS 9.2 critical vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host…
- CVE-2026-92953 CVSS 9.3 critical vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use…
- CVE-2026-92952 CVSS 8.9 high vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction…
- CVE-2026-92951 CVSS 9.4 critical vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring…
- CVE-2026-92950 CVSS 9.3 critical vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host…
- CVE-2026-92949 CVSS 6.3 medium vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed…
- CVE-2026-92948 CVSS 9.4 critical vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and…
- CVE-2026-92947 CVSS 10.0 critical vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from…
- CVE-2026-92946 CVSS 10.0 critical vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that…
- CVE-2026-92945 CVSS 2.3 low vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead…
- CVE-2026-92944 CVSS 9.3 critical vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's…
- CVE-2026-92942 CVSS 8.7 high vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous…
- CVE-2026-92941 CVSS 10.0 critical vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call…
- CVE-2026-92940 CVSS 10.0 critical vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly…