Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vm2 — Vulnerabilities & Security Advisories 41

All 41 CVE vulnerabilities found in vm2, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the vm2 product, focusing on software security weaknesses and associated risk tags. It systematically collects and organizes known security flaws, ranging from remote code execution to denial-of-service issues, covering a broad historical timeframe from early releases to recent updates. The database includes entries sourced from vendor advisories, third-party security researchers, and automated scanners to provide a comprehensive view of the threat landscape. Visitors can use this repository to track specific advisories issued by the vendor, allowing for timely response to critical patches. Users interested in the broader implications of certain flaw types can analyze trends to understand the characteristics and severity of specific weakness classes. Additionally, the platform enables detailed lookup of a product’s vulnerability history, helping developers and security teams assess past exposure and measure the effectiveness of ongoing remediation efforts. This structured approach supports informed decision-making regarding patching cycles and architectural improvements. By centralizing disparate data sources into a single, searchable interface, the page reduces the time required to investigate security incidents and enhances overall visibility into the product's compliance and risk posture.

Vendor: patriksimek

CVE IDTitleCVSSSeverityPublished
CVE-2026-47141 vm2: NodeVM observability builtins leak host process and HTTP request data CWE-668--2026-06-12
CVE-2026-47210 vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass CWE-913 9.8 Critical2026-06-12
CVE-2026-47208 vm2: Sandbox Breakout Using Promise Species CWE-913 10.0 Critical2026-06-12
CVE-2026-47140 vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution CWE-693 10.0 Critical2026-06-12
CVE-2026-47139 vm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_server CWE-693 8.6 High2026-06-12
CVE-2026-47137 vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE CWE-913 10.0 Critical2026-06-12
CVE-2026-47135 vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks CWE-693 8.7 High2026-06-12
CVE-2026-47131 vm2: Sandbox Escape CWE-913 10.0 Critical2026-06-12
CVE-2026-47209 vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain CWE-693 8.6 High2026-06-12
CVE-2026-44005 vm2: Sandbox escape CWE-1321 10.0 Critical2026-05-13
CVE-2026-45411 vm2: Sandbox Breakout Using Async Generator CWE-668 9.8 Critical2026-05-13
CVE-2026-44009 vm2: Sandbox Breakout Through Null Proto Exception CWE-668 9.8 Critical2026-05-13
CVE-2026-44008 vm2: Snabox breakout via `neutralizeArraySpeciesBatch` CWE-668 9.8 Critical2026-05-13
CVE-2026-44007 vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution CWE-284 9.1 Critical2026-05-13
CVE-2026-44006 vm2: Sandbox Escape CWE-94 10.0 Critical2026-05-13
CVE-2026-44004 vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass) CWE-770 7.5 High2026-05-13
CVE-2026-44003 vm2: Transformer Fast-Path Bypass Exposes Internal State Variable CWE-693 5.3 Medium2026-05-13
CVE-2026-44002 vm2: Host File Path Disclosure via Stack Trace Information Leak CWE-209 5.8 Medium2026-05-13
CVE-2026-44001 vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) CWE-248 8.6 High2026-05-13
CVE-2026-44000 vm2: sandbox boundary bypass via host Promise resolution preserving host object identity CWE-693 6.5 Medium2026-05-13
CVE-2026-43999 vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape CWE-863 9.9 Critical2026-05-13
CVE-2026-43998 vm2: NodeVM require.root bypass via symlink traversal allows sandbox escape CWE-59 8.5 High2026-05-13
CVE-2026-43997 vm2: Sandbox Escape CWE-94 10.0 Critical2026-05-13
CVE-2026-26956 vm2: WASM Sandbox Escape (Node 25 only) CWE-693 9.8 Critical2026-05-04
CVE-2026-26332 vm2: Sandbox Escape CWE-94 9.8 Critical2026-05-04
CVE-2026-24781 vm2: Sandbox Breakout Through Inspect CWE-94 9.8 Critical2026-05-04
CVE-2026-24120 vm2: Sandbox Breakout Through Promise Species CWE-693 9.8 Critical2026-05-04
CVE-2026-24118 VM2 Sandbox Breakout Through __lookupGetter__ CWE-94 9.8 Critical2026-05-04
CVE-2026-22709 vm2 has a Sandbox Escape CWE-94 9.8 Critical2026-01-26
CVE-2023-37903 Sandbox Escape in vm2 CWE-78 9.8 Critical2023-07-21

All 41 known CVE vulnerabilities affecting vm2 with full Chinese analysis, references, and POCs where available.