URL has been copied successfully!
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution

A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system.The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0 on the CVSS scoring system.”In vm2 for version 3.10.0, Promise.prototype.then Promise.prototype.catch

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link