pkg:npm/vm2
41 total CVEsCRITICAL29HIGH7MEDIUM4
✅ Check your installed version
All known vulnerabilities
- CRITICAL10.0CVE-2026-47140NodeVM builtin denylist bypass via process and inspector/promises allows host code executionfrom 0, < 3.11.4
- CRITICAL10.0CVE-2026-47137vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCEfrom 0, < 3.11.4
- from 0, < 3.11.4
- from 0, < 3.11.4
- >= 3.9.6, < 3.11.0
- from 0, < 3.11.0
- from 0, < 3.11.0
- CRITICAL10.0CVE-2022-36067vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on hostfrom 0, < 3.9.11
- CRITICAL9.9CVE-2026-43999vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape>= 3.10.5, < 3.11.0
- from 0, < 3.11.4
- from 0, < 3.11.3
- from 0, < 3.11.2
- from 0, < 3.11.2
- >= 3.10.4, < 3.10.5
- from 0, < 3.11.0
- from 0, < 3.11.0
- from 0, < 3.10.5
- from 0, < 3.11.0
- from 0, < 3.10.2
- from 0, < 3.10.0
- from 0, <= 3.9.19
- from 0, < 3.9.18
- from 0, < 3.9.17
- from 0, < 3.9.16
- from 0, < 3.9.15
- from 0, < 3.9.10
- from 0, < 3.9.6
- from 0, < 3.9.4
- CRITICAL9.1CVE-2026-44007vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command executionfrom 0, < 3.11.1
- HIGH8.7CVE-2026-47135vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checksfrom 0, < 3.11.4
- HIGH8.6CVE-2026-47139NodeVM network builtin exclusions bypass via internal _http_client and _http_serverfrom 0, < 3.11.4
- HIGH8.6CVE-2026-47209vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainfrom 0, < 3.11.4
- HIGH8.6CVE-2026-44001vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)from 0, < 3.11.0
- HIGH8.5CVE-2026-43998vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape>= 3.10.5, < 3.11.0
- from 0, < 3.6.11
- HIGH7.5CVE-2026-44004vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustionfrom 0, < 3.11.0
- MEDIUM6.5CVE-2026-44000vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundaryfrom 0, < 3.11.0
- MEDIUM5.8CVE-2026-44002vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leakfrom 0, < 3.11.0
- from 0, < 3.11.0
- from 0, < 3.9.18
- from 0, < 3.11.4