Package impact

npm NPM / vm2

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44006 critical 10.0 10.0 22d ago vm2 has a Sandbox Escape Vulnerability
CVE-2026-44005 critical 10.0 10.0 22d ago vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
CVE-2026-43997 critical 10.0 10.0 22d ago vm2 Access to Host Object Enables Sandbox Escape
CVE-2026-26332 critical 10.0 10.0 1mo ago VM2 Has a Sandbox Escape Issue via SuppressedError
CVE-2026-43999 critical 9.9 9.9 22d ago vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
CVE-2026-45411 critical 9.8 9.8 22d ago vm2 Has a Sandbox Breakout Using Async Generator
CVE-2026-44009 critical 9.8 9.8 22d ago vm2 has Sandbox Breakout Through Null Proto Exception
CVE-2026-44008 critical 9.8 9.8 22d ago vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-26956 critical 9.8 9.8 1mo ago VM2 Has a WASM Sandbox Escape (Node 25 only)
CVE-2026-24781 critical 9.8 9.8 1mo ago VM2 Has Sandbox Breakout Through Inspect Function
CVE-2026-24120 critical 9.8 9.8 1mo ago VM2 Has Sandbox Breakout Through Promise Species
CVE-2026-24118 critical 9.8 9.8 1mo ago VM2 Sandbox Breakout Through __lookupGetter__
CVE-2026-44007 critical 9.1 9.1 22d ago vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution