Technology · npm
vm2 (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 82 vulnerabilities in vm2 (npm): 0 in the last 7 days and 39 in the last 90 days, 41 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93606, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 39
- Critical, all time
- 41
- Exploited in the wild
- 0
About vm2 (npm)
Node.js virtual machine library for safely executing untrusted code in an isolated context.
Latest vm2 (npm) vulnerabilities
- CVE-2026-93606: vm2 sandbox escape via Promise Symbol.species hijackcriticalCVSS 10EPSS 0.7%
- CVE-2026-93605: vm2 NodeVM sandbox escape via child_process denylist omissioncriticalCVSS 10EPSS 0.7%
- CVE-2026-93604: vm2 sandbox escape via crypto.setFips exposurehighCVSS 7.2EPSS 0.4%
- CVE-2026-93603: vm2 sandbox escape via nullish this receivercriticalCVSS 10EPSS 0.7%
- CVE-2026-92963: vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-92962: vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the…mediumCVSS 4EPSS 0.2%
- CVE-2026-92961: vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors…highCVSS 7.5EPSS 0.5%
- CVE-2026-92960: vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox…criticalCVSS 10EPSS 0.5%
- CVE-2026-92959: vm2 allowAsync bypass via Promise thenable assimilationhighCVSS 7.1EPSS 0.4%
- CVE-2026-92958: vm2 builtin denylist bypass in NodeVMhighCVSS 8.5EPSS 0.4%
- CVE-2026-92957: vm2 NodeVM builtin deny-list bypass via node:-prefixed specifierscriticalCVSS 9.9EPSS 0.6%
- CVE-2026-92956: vm2 sandbox escape via WebAssembly.compileStreamingcriticalCVSS 10EPSS 0.6%
- CVE-2026-92955: vm2 sandbox escape in NodeVM via __proto__ manipulationcriticalCVSS 10EPSS 0.7%
- CVE-2026-92954: vm2 host Promise rejection denial of servicehighCVSS 8.6EPSS 0.5%
- CVE-2026-92953: vm2 prototype pollution in TypedArray and ArrayBuffercriticalCVSS 10EPSS 0.5%
- CVE-2026-92952: vm2 sandbox symbol filtering bypass in Node.js symbol isolationmediumCVSS 6.8EPSS 0.5%
- CVE-2026-92951: vm2 module allowlist bypass via substring matchingcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-92950: vm2 sandbox escape in CLI tool via requirehighCVSS 8.6EPSS 0.2%
- CVE-2026-92949: vm2 sandbox bypass via accessor descriptor on frozen objectsmediumCVSS 4EPSS 0.3%
- CVE-2026-92948: vm2 NodeVM builtin allowlist bypass and sandbox escapecriticalCVSS 9.9EPSS 0.7%
- CVE-2026-92947: vm2 memory disclosure via shared Buffer poolcriticalCVSS 10EPSS 0.5%
- CVE-2026-92946: vm2 remote code execution in NodeVM require.externalcriticalCVSS 10EPSS 0.9%
- CVE-2026-92945: vm2 module allowlist bypass via prefix matchingmediumCVSS 4.2EPSS 0.3%
- CVE-2026-92944: vm2 sandbox escape via Promise.prototype.finally() on Node.js 26criticalCVSS 9.8EPSS 0.8%
- CVE-2026-92942: vm2 timeout bypass via FinalizationRegistry callbackhighCVSS 7.5EPSS 0.5%
Most severe vm2 (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-92937: vm2 sandbox escape in Promise rejection handlingcriticalCVSS 10EPSS 1.0%
- CVE-2026-92946: vm2 remote code execution in NodeVM require.externalcriticalCVSS 10EPSS 0.9%
- CVE-2026-47208: patriksimek vm2 sandbox breakout via Promise species hijackcriticalCVSS 10EPSS 0.8%
- CVE-2026-44005: patriksimek vm2 sandbox escape via host prototype mutationcriticalCVSS 10EPSS 0.8%
- CVE-2026-47140: patriksimek vm2 sandbox escape via NodeVM builtin denylist bypasscriticalCVSS 10EPSS 0.8%
- CVE-2026-44006: patriksimek vm2 sandbox escape via arbitrary prototype accesscriticalCVSS 10EPSS 0.8%
- CVE-2026-43997: patriksimek vm2 sandbox escape via host object leakagecriticalCVSS 10EPSS 0.8%
- CVE-2026-93605: vm2 NodeVM sandbox escape via child_process denylist omissioncriticalCVSS 10EPSS 0.7%
- CVE-2026-93603: vm2 sandbox escape via nullish this receivercriticalCVSS 10EPSS 0.7%
- CVE-2026-93606: vm2 sandbox escape via Promise Symbol.species hijackcriticalCVSS 10EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 3 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 34 | 20 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/vm2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "vm2 (npm) vulnerabilities", https://junglewise.ai/threats/technologies/vm2, 26 September 2026.