CVE-2026-24120
critical · 9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.10.5.
9.8
CVSS
0.9%
EPSS (exploit prob.)
58th
EPSS percentile
2026-05-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94CWE-693CWE-807
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vm2_project | vm2 | < 3.10.5 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/patriksimek/vm2/releases/tag/v3.10.5
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p
- https://access.redhat.com/security/cve/CVE-2026-24120
- https://bugzilla.redhat.com/show_bug.cgi?id=2466529
- https://github.com/patriksimek/vm2/security/advisories/GHSA-qvjj-29qf-hp7p
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24120.json
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-24120