---
id: CVE-2026-43997
title: vm2 is an open source vm/sandbox for Node.js
summary: >-
  vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible
  to obtain the host Object. There are various ways to use the host Object, to
  escape the sandbox, one example would be using
  HostObject.getOwnPropertySymbols to…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-653
vendor: vm2_project
product: vm2
affected:
  - vm2 < 3.11.0
patched:
  - vm2 3.11.0
published: '2026-05-13'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43997'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:50850'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-43997'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2477203'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-47x8-96vw-5wg6'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43997.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00767
epssPercentile: 0.53544
ingestedAt: '2026-08-06T13:59:37.262Z'
---

## Overview

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.

## Affected

- `vm2 < 3.11.0`

## Remediation

Upgrade past the affected range:

- `vm2 3.11.0`
