CVE-2026-44001High· 8.6▾ Twilightvm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejectio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2) only sanitized the onRejected callback in .then() and .catch() overrides and did not address the executor-to-unhandledRejection path. This vulnerability is fixed in 3.11.0.
vm2 < 3.11.0Upgrade past the affected range:
vm2 3.11.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92954High· 8.6vm2 is a sandbox library for running untrusted JavaScript in Node.js
CVE-2026-45411Critical· 9.8vm2 is an open source vm/sandbox for Node.js
CVE-2026-44009Critical· 9.8vm2 is an open source vm/sandbox for Node.js
CVE-2026-44008Critical· 9.8vm2 is an open source vm/sandbox for Node.js
CVE-2026-44007Critical· 9.1vm2 is an open source vm/sandbox for Node.js
CVE-2026-44006Critical· 10.0vm2 is an open source vm/sandbox for Node.js