Vendorsvm2 Projectvm2all versions
Vulnerabilities

vm2 Project vm2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2023-30547
Sandbox Escape in vm2
Published 2023-04-17 · Modified
10.0EPSS 0.721
CVE-2023-29017
vm2 Sandbox Escape vulnerability
Published 2023-04-06 · Modified
10.0EPSS 0.632
CVE-2022-36067
vm2 vulnerable to Sandbox Escape before v3.9.11
Published 2022-09-06 · Modified
10.0EPSS 0.479
CVE-2023-32314
Sandbox Escape
Published 2023-05-15 · Modified
10.0EPSS 0.081
CVE-2023-37903
Sandbox Escape in vm2
Published 2023-07-21 · Modified
10.0EPSS 0.042
CVE-2023-37466
vm2 Sandbox Escape vulnerability
Published 2023-07-13 · Modified
10.0EPSS 0.039
CVE-2023-29199
vm2 Sandbox escape vulnerability
Published 2023-04-14 · Modified
10.0EPSS 0.039
CVE-2021-23449
Sandbox Bypass
Published 2021-10-18 · Modified
10.0EPSS 0.036
CVE-2021-23555
Sandbox Bypass
Published 2022-02-11 · Modified
10.0EPSS 0.029
CVE-2026-22709
vm2 has a Sandbox Escape
Published 2026-01-26 · Analyzed
10.0EPSS 0.013
CVE-2026-43997
vm2: Sandbox Escape
Published 2026-05-13 · Modified
10.0EPSS 0.010
CVE-2026-44005
vm2: Sandbox escape
Published 2026-05-13 · Modified
10.0EPSS 0.008
CVE-2026-44006
vm2: Sandbox Escape
Published 2026-05-13 · Modified
10.0EPSS 0.008
CVE-2026-26332
vm2: Sandbox Escape
Published 2026-05-04 · Modified
10.0EPSS 0.007
CVE-2026-43999
vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
Published 2026-05-13 · Modified
9.9EPSS 0.010
CVE-2026-44007
vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution
Published 2026-05-13 · Modified
9.9EPSS 0.010
CVE-2022-25893
Arbitrary Code Execution
Published 2022-12-21 · Modified
9.8EPSS 0.014
CVE-2026-24781
vm2: Sandbox Breakout Through Inspect
Published 2026-05-04 · Modified
9.8EPSS 0.012
CVE-2026-26956
vm2: WASM Sandbox Escape (Node 25 only)
Published 2026-05-04 · Modified
9.8EPSS 0.009
CVE-2026-24118
VM2 Sandbox Breakout Through __lookupGetter__
Published 2026-05-04 · Modified
9.8EPSS 0.009
CVE-2026-24120
vm2: Sandbox Breakout Through Promise Species
Published 2026-05-04 · Modified
9.8EPSS 0.009
CVE-2026-44008
vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
Published 2026-05-13 · Modified
9.8EPSS 0.009
CVE-2026-44009
vm2: Sandbox Breakout Through Null Proto Exception
Published 2026-05-13 · Modified
9.8EPSS 0.008
CVE-2026-45411
vm2: Sandbox Breakout Using Async Generator
Published 2026-05-13 · Modified
9.8EPSS 0.006
CVE-2026-44001
vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
Published 2026-05-13 · Modified
8.6EPSS 0.004
CVE-2026-44004
vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
Published 2026-05-13 · Modified
8.6EPSS 0.004
CVE-2026-43998
vm2: NodeVM require.root bypass via symlink traversal allows sandbox escape
Published 2026-05-13 · Modified
8.5EPSS 0.007
CVE-2019-10761
Sandbox Bypass
Published 2022-07-13 · Modified
8.3EPSS 0.013
CVE-2026-44000
vm2: sandbox boundary bypass via host Promise resolution preserving host object identity
Published 2026-05-13 · Analyzed
7.2EPSS 0.002
CVE-2026-44003
vm2: Transformer Fast-Path Bypass Exposes Internal State Variable
Published 2026-05-13 · Analyzed
5.8EPSS 0.002
CVE-2026-44002
vm2: Host File Path Disclosure via Stack Trace Information Leak
Published 2026-05-13 · Analyzed
5.8EPSS 0.002
CVE-2023-32313
Inspect method manipulation in vm2
Published 2023-05-15 · Modified
5.3EPSS 0.008