Critical remote code execution in vm2, a widely used Node.js sandbox library

· · Sept. 2, 2026, 10:04 p.m.
Summary
GitLab's Threat Research Group has identified a critical sandbox escape vulnerability (CVSS 3.1: 10.0) in the vm2 Node.js sandboxing library, where certain configurations allow untrusted code to execute unsafely on the host system. Developers are urged to upgrade to vm2 Version 3.11.7 and implement additional security measures, including restricting configuration settings to mitigate risks from similar vulnerabilities.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →