vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.
Metrics
Affected Vendors & Products
References
History
Mon, 04 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5. | |
| Title | vm2: Sandbox Breakout Through Promise Species | |
| Weaknesses | CWE-693 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-04T16:31:13.639Z
Reserved: 2026-01-21T18:38:22.473Z
Link: CVE-2026-24120
No data.
Status : Received
Published: 2026-05-04T17:16:21.813
Modified: 2026-05-04T17:16:21.813
Link: CVE-2026-24120
No data.
OpenCVE Enrichment
Updated: 2026-05-04T19:15:06Z