{"schema_version":1,"title":"vm2 (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 83 vulnerabilities in vm2 (npm): 1 in the last 7 days and 40 in the last 90 days, 41 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100722, was published on 27 September 2026.","url":"https://junglewise.ai/threats/technologies/vm2","json_url":"https://junglewise.ai/threats/technologies/vm2.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/vm2","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":15,"all_time":83,"critical":41,"exploited":0,"last_7_days":1,"last_30_days":35,"last_90_days":40,"last_365_days":71},"latest":[{"cve":"CVE-2026-100722","cvss":6.8,"slug":"cve-2026-100722-vm2-before-3-12-2-does-not-apply-host-side-promise-rejection","title":"vm2 unhandled Promise rejection in construct trap","severity":"medium","exploited":false,"published_at":"2026-09-27T02:17:18.817+00:00","url":"https://junglewise.ai/threats/cve-2026-100722-vm2-before-3-12-2-does-not-apply-host-side-promise-rejection"},{"cve":"CVE-2026-93606","cvss":10,"epss":0.0071,"slug":"cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack","title":"vm2 sandbox escape via Promise Symbol.species hijack","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.5+00:00","url":"https://junglewise.ai/threats/cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack"},{"cve":"CVE-2026-93605","cvss":10,"epss":0.0073,"slug":"cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission","title":"vm2 NodeVM sandbox escape via child_process denylist omission","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.34+00:00","url":"https://junglewise.ai/threats/cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission"},{"cve":"CVE-2026-93604","cvss":7.2,"epss":0.0035,"slug":"cve-2026-93604-vm2-sandbox-escape-via-crypto-setfips-exposure","title":"vm2 sandbox escape via crypto.setFips exposure","severity":"high","exploited":false,"published_at":"2026-09-18T14:19:12.167+00:00","url":"https://junglewise.ai/threats/cve-2026-93604-vm2-sandbox-escape-via-crypto-setfips-exposure"},{"cve":"CVE-2026-93603","cvss":10,"epss":0.0073,"slug":"cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver","title":"vm2 sandbox escape via nullish this receiver","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.003+00:00","url":"https://junglewise.ai/threats/cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver"},{"cve":"CVE-2026-92963","cvss":5.3,"epss":0.0034,"slug":"cve-2026-92963-vm2-internal-state-disclosure-in-computed-key-access","title":"vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attac","severity":"medium","exploited":false,"published_at":"2026-09-17T14:18:02.783+00:00","url":"https://junglewise.ai/threats/cve-2026-92963-vm2-internal-state-disclosure-in-computed-key-access"},{"cve":"CVE-2026-92962","cvss":4,"epss":0.0016,"slug":"cve-2026-92962-vm2-defense-invariant-11-violation-in-stack-trace-formatter","title":"vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function","severity":"medium","exploited":false,"published_at":"2026-09-17T14:18:02.61+00:00","url":"https://junglewise.ai/threats/cve-2026-92962-vm2-defense-invariant-11-violation-in-stack-trace-formatter"},{"cve":"CVE-2026-92961","cvss":7.5,"epss":0.0053,"slug":"cve-2026-92961-vm2-memory-exhaustion-dos-via-bufferalloclimit-bypass","title":"vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to al","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:02.447+00:00","url":"https://junglewise.ai/threats/cve-2026-92961-vm2-memory-exhaustion-dos-via-bufferalloclimit-bypass"},{"cve":"CVE-2026-92960","cvss":10,"epss":0.0047,"slug":"cve-2026-92960-vm2-nodevm-builtin-wildcard-sandbox-escape-via-os-and-dns-modules","title":"vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:02.29+00:00","url":"https://junglewise.ai/threats/cve-2026-92960-vm2-nodevm-builtin-wildcard-sandbox-escape-via-os-and-dns-modules"},{"cve":"CVE-2026-92959","cvss":7.1,"epss":0.0045,"slug":"cve-2026-92959-vm2-allowasync-bypass-via-promise-thenable-assimilation","title":"vm2 allowAsync bypass via Promise thenable assimilation","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:02.13+00:00","url":"https://junglewise.ai/threats/cve-2026-92959-vm2-allowasync-bypass-via-promise-thenable-assimilation"},{"cve":"CVE-2026-92958","cvss":8.5,"epss":0.0038,"slug":"cve-2026-92958-vm2-builtin-denylist-bypass-in-nodevm","title":"vm2 builtin denylist bypass in NodeVM","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:01.97+00:00","url":"https://junglewise.ai/threats/cve-2026-92958-vm2-builtin-denylist-bypass-in-nodevm"},{"cve":"CVE-2026-92957","cvss":9.9,"epss":0.0057,"slug":"cve-2026-92957-vm2-nodevm-builtin-deny-list-bypass-via-node-prefixed-specifiers","title":"vm2 NodeVM builtin deny-list bypass via node:-prefixed specifiers","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:01.813+00:00","url":"https://junglewise.ai/threats/cve-2026-92957-vm2-nodevm-builtin-deny-list-bypass-via-node-prefixed-specifiers"},{"cve":"CVE-2026-92956","cvss":10,"epss":0.0059,"slug":"cve-2026-92956-vm2-sandbox-escape-via-webassembly-compilestreaming","title":"vm2 sandbox escape via WebAssembly.compileStreaming","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:01.64+00:00","url":"https://junglewise.ai/threats/cve-2026-92956-vm2-sandbox-escape-via-webassembly-compilestreaming"},{"cve":"CVE-2026-92955","cvss":10,"epss":0.0071,"slug":"cve-2026-92955-vm2-sandbox-escape-in-nodevm-via-proto-manipulation","title":"vm2 sandbox escape in NodeVM via __proto__ manipulation","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:01.48+00:00","url":"https://junglewise.ai/threats/cve-2026-92955-vm2-sandbox-escape-in-nodevm-via-proto-manipulation"},{"cve":"CVE-2026-92954","cvss":8.6,"epss":0.0049,"slug":"cve-2026-92954-vm2-host-promise-rejection-denial-of-service","title":"vm2 host Promise rejection denial of service","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:01.32+00:00","url":"https://junglewise.ai/threats/cve-2026-92954-vm2-host-promise-rejection-denial-of-service"},{"cve":"CVE-2026-92953","cvss":10,"epss":0.005,"slug":"cve-2026-92953-vm2-prototype-pollution-in-typedarray-and-arraybuffer","title":"vm2 prototype pollution in TypedArray and ArrayBuffer","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:01.16+00:00","url":"https://junglewise.ai/threats/cve-2026-92953-vm2-prototype-pollution-in-typedarray-and-arraybuffer"},{"cve":"CVE-2026-92952","cvss":6.8,"epss":0.0046,"slug":"cve-2026-92952-vm2-sandbox-symbol-filtering-bypass-in-node-js-symbol-isolation","title":"vm2 sandbox symbol filtering bypass in Node.js symbol isolation","severity":"medium","exploited":false,"published_at":"2026-09-17T14:18:00.987+00:00","url":"https://junglewise.ai/threats/cve-2026-92952-vm2-sandbox-symbol-filtering-bypass-in-node-js-symbol-isolation"},{"cve":"CVE-2026-92951","cvss":9.9,"epss":0.0054,"slug":"cve-2026-92951-vm2-module-allowlist-bypass-via-substring-matching","title":"vm2 module allowlist bypass via substring matching","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:00.827+00:00","url":"https://junglewise.ai/threats/cve-2026-92951-vm2-module-allowlist-bypass-via-substring-matching"},{"cve":"CVE-2026-92950","cvss":8.6,"epss":0.002,"slug":"cve-2026-92950-vm2-sandbox-escape-in-cli-tool-via-require","title":"vm2 sandbox escape in CLI tool via require","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:00.637+00:00","url":"https://junglewise.ai/threats/cve-2026-92950-vm2-sandbox-escape-in-cli-tool-via-require"},{"cve":"CVE-2026-92949","cvss":4,"epss":0.0032,"slug":"cve-2026-92949-vm2-sandbox-bypass-via-accessor-descriptor-on-frozen-objects","title":"vm2 sandbox bypass via accessor descriptor on frozen objects","severity":"medium","exploited":false,"published_at":"2026-09-17T14:18:00.463+00:00","url":"https://junglewise.ai/threats/cve-2026-92949-vm2-sandbox-bypass-via-accessor-descriptor-on-frozen-objects"},{"cve":"CVE-2026-92948","cvss":9.9,"epss":0.0065,"slug":"cve-2026-92948-vm2-nodevm-builtin-allowlist-bypass-and-sandbox-escape","title":"vm2 NodeVM builtin allowlist bypass and sandbox escape","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:00.31+00:00","url":"https://junglewise.ai/threats/cve-2026-92948-vm2-nodevm-builtin-allowlist-bypass-and-sandbox-escape"},{"cve":"CVE-2026-92947","cvss":10,"epss":0.0048,"slug":"cve-2026-92947-vm2-memory-disclosure-via-shared-buffer-pool","title":"vm2 memory disclosure via shared Buffer pool","severity":"critical","exploited":false,"published_at":"2026-09-17T14:18:00.14+00:00","url":"https://junglewise.ai/threats/cve-2026-92947-vm2-memory-disclosure-via-shared-buffer-pool"},{"cve":"CVE-2026-92946","cvss":10,"epss":0.0086,"slug":"cve-2026-92946-vm2-remote-code-execution-in-nodevm-require-external","title":"vm2 remote code execution in NodeVM require.external","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:59.963+00:00","url":"https://junglewise.ai/threats/cve-2026-92946-vm2-remote-code-execution-in-nodevm-require-external"},{"cve":"CVE-2026-92945","cvss":4.2,"epss":0.0028,"slug":"cve-2026-92945-vm2-module-allowlist-bypass-via-prefix-matching","title":"vm2 module allowlist bypass via prefix matching","severity":"medium","exploited":false,"published_at":"2026-09-17T14:17:59.807+00:00","url":"https://junglewise.ai/threats/cve-2026-92945-vm2-module-allowlist-bypass-via-prefix-matching"},{"cve":"CVE-2026-92944","cvss":9.8,"epss":0.0084,"slug":"cve-2026-92944-vm2-sandbox-escape-via-promise-prototype-finally-on-node-js-26","title":"vm2 sandbox escape via Promise.prototype.finally() on Node.js 26","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:59.623+00:00","url":"https://junglewise.ai/threats/cve-2026-92944-vm2-sandbox-escape-via-promise-prototype-finally-on-node-js-26"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":3,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":20,"exploited":0,"vulnerabilities":34},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"},{"name":"9router (npm)","slug":"9router","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/9router"}],"technology":{"hub":true,"name":"vm2 (npm)","slug":"vm2","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"category":"library","homepage":"https://github.com/patriksimek/vm2","repo_url":"https://github.com/patriksimek/vm2","description":"Node.js virtual machine library for safely executing untrusted code in an isolated context.","url":"https://junglewise.ai/threats/technologies/vm2"},"most_severe":[{"cve":"CVE-2026-92937","cvss":10,"epss":0.0103,"slug":"cve-2026-92937-vm2-sandbox-escape-in-promise-rejection-handling","title":"vm2 sandbox escape in Promise rejection handling","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:58.517+00:00","url":"https://junglewise.ai/threats/cve-2026-92937-vm2-sandbox-escape-in-promise-rejection-handling"},{"cve":"CVE-2026-92946","cvss":10,"epss":0.0086,"slug":"cve-2026-92946-vm2-remote-code-execution-in-nodevm-require-external","title":"vm2 remote code execution in NodeVM require.external","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:59.963+00:00","url":"https://junglewise.ai/threats/cve-2026-92946-vm2-remote-code-execution-in-nodevm-require-external"},{"cve":"CVE-2026-47208","cvss":10,"epss":0.0083,"slug":"cve-2026-47208-patriksimek-vm2-sandbox-breakout-via-promise-species-hijack","title":"patriksimek vm2 sandbox breakout via Promise species hijack","severity":"critical","exploited":false,"published_at":"2026-06-12T15:16:28.767+00:00","url":"https://junglewise.ai/threats/cve-2026-47208-patriksimek-vm2-sandbox-breakout-via-promise-species-hijack"},{"cve":"CVE-2026-44005","cvss":10,"epss":0.0083,"slug":"cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation","title":"patriksimek vm2 sandbox escape via host prototype mutation","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation"},{"cve":"CVE-2026-47140","cvss":10,"epss":0.0082,"slug":"cve-2026-47140-patriksimek-vm2-sandbox-escape-via-nodevm-builtin-denylist-bypass","title":"patriksimek vm2 sandbox escape via NodeVM builtin denylist bypass","severity":"critical","exploited":false,"published_at":"2026-06-12T15:16:28.4+00:00","url":"https://junglewise.ai/threats/cve-2026-47140-patriksimek-vm2-sandbox-escape-via-nodevm-builtin-denylist-bypass"},{"cve":"CVE-2026-44006","cvss":10,"epss":0.0077,"slug":"cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access","title":"patriksimek vm2 sandbox escape via arbitrary prototype access","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.387+00:00","url":"https://junglewise.ai/threats/cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access"},{"cve":"CVE-2026-43997","cvss":10,"epss":0.0077,"slug":"cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage","title":"patriksimek vm2 sandbox escape via host object leakage","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.177+00:00","url":"https://junglewise.ai/threats/cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage"},{"cve":"CVE-2026-93605","cvss":10,"epss":0.0073,"slug":"cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission","title":"vm2 NodeVM sandbox escape via child_process denylist omission","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.34+00:00","url":"https://junglewise.ai/threats/cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission"},{"cve":"CVE-2026-93603","cvss":10,"epss":0.0073,"slug":"cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver","title":"vm2 sandbox escape via nullish this receiver","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.003+00:00","url":"https://junglewise.ai/threats/cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver"},{"cve":"CVE-2026-93606","cvss":10,"epss":0.0071,"slug":"cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack","title":"vm2 sandbox escape via Promise Symbol.species hijack","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.5+00:00","url":"https://junglewise.ai/threats/cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}