---
id: CVE-2026-44008
title: vm2 is an open source vm/sandbox for Node.js
summary: >-
  vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method
  neutralizeArraySpeciesBatch works with objects from the other side but can
  call into this side via getter on the array prototype exposing objects of the
  wrong …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-668
  - CWE-1100
vendor: vm2_project
product: vm2
affected:
  - vm2 < 3.11.2
patched:
  - vm2 3.11.2
published: '2026-05-13'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44008'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-9qj6-qjgg-37qq'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:50850'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44008'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2477201'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44008.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00851
epssPercentile: 0.56195
ingestedAt: '2026-08-06T13:59:37.921Z'
---

## Overview

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fixed in 3.11.2.

## Affected

- `vm2 < 3.11.2`

## Remediation

Upgrade past the affected range:

- `vm2 3.11.2`
