26 Total CVEs
26 AI Analyzed
0 CISA KEV
20 Critical

Profile

0% ended up actively exploited 0 of 26 added to CISA KEV
77% rated critical (CVSS 9.0+) 20 critical, 6 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

26 CVEs in the last 12 months

Products

  • vm220
  • vm2 (Node.js sandbox)3

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-26 of 26 CVEs
CVE-2026-47698
Analyzed
9.8
patriksimek vm2

The vm2 sandbox for Node.js fails to block prototype chain manipulation, allowing unauthenticated attackers to escape the sandbox and execute arbitrar...

2026-08-18
CVE-2026-47686
Analyzed
9.9
patriksimek vm2

A sandbox escape vulnerability in the vm2 library allows attackers to bypass security restrictions and execute arbitrary host commands by manipulating...

2026-08-18
CVE-2026-47683
Analyzed
8.7
patriksimek vm2

vm2 is an open source vm/sandbox for Node

2026-08-18
CVE-2026-47210
Analyzed
9.8
patriksimek vm2

The vm2 sandbox for Node.js is vulnerable to a sandbox escape that allows arbitrary code execution in the host process when using WebAssembly JSPI.

2026-06-13
CVE-2026-47209
Analyzed
8.6
patriksimek vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47208
Analyzed
10
patriksimek vm2

A sandbox breakout vulnerability in vm2 allows unauthenticated attackers to execute arbitrary commands on the host system via promise manipulation.

2026-06-13
CVE-2026-47140
Analyzed
10
patriksimek vm2

An incomplete denylist of Node.js builtins in vm2 allows unauthenticated attackers to escape the sandbox and execute code in the host process.

2026-06-13
CVE-2026-47139
Analyzed
8.6
patriksimek vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47137
Analyzed
10
patriksimek vm2

An improper security check implementation in vm2 allows unauthenticated attackers to bypass sandbox restrictions and achieve remote code execution.

2026-06-13
CVE-2026-47135
Analyzed
8.7
patriksimek vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47131
Analyzed
10
patriksimek vm2

A sandbox escape vulnerability in vm2 allows unauthenticated attackers to execute arbitrary code on the host system via prototype mutation.

2026-06-13
CVE-2026-45411
Analyzed
9.8
patriksimek vm2

The vm2 sandbox library for Node.js is vulnerable to sandbox escape via async generator manipulation, allowing arbitrary command execution.

2026-05-14
CVE-2026-44009
Analyzed
9.8
patriksimek vm2

The vm2 sandbox library for Node.js is vulnerable to sandbox escape, potentially allowing arbitrary command execution on the host system.

2026-05-14
CVE-2026-44008
Analyzed
9.8
patriksimek vm2

The vm2 sandbox for Node.js is vulnerable to an array species batch neutralization flaw, allowing attackers to escape the sandbox and execute arbitrar...

2026-05-14
CVE-2026-44006
Analyzed
10
patriksimek vm2

The vm2 sandbox for Node.js is vulnerable to prototype access, allowing attackers to reach arbitrary prototypes and escape the sandbox.

2026-05-14
CVE-2026-44005
Analyzed
10
patriksimek vm2

The vm2 sandbox for Node.js is vulnerable to prototype pollution, allowing sandboxed code to mutate host-realm objects and escape the environment.

2026-05-14
CVE-2026-44001
Analyzed
8.6
patriksimek Multiple Products

vm2 is an open source vm/sandbox for Node

2026-05-14
CVE-2026-43999
Analyzed
9.9
patriksimek vm2

The vm2 sandbox for Node.js contains a bypass in its builtin allowlist, enabling unauthorized access to restricted modules and arbitrary code executio...

2026-05-14
CVE-2026-43998
Analyzed
8.5
patriksimek Multiple Products

vm2 is an open source vm/sandbox for Node

2026-05-14
CVE-2026-43997
Analyzed
10
patriksimek vm2

The vm2 sandbox for Node.js is vulnerable to a host object escape, allowing attackers to access the host environment by leveraging native symbols.

2026-05-14
CVE-2026-26956
Analyzed
9.8
patriksimek vm2

A full sandbox escape vulnerability in vm2 version 3.10.4 allows attackers to access the host process object and execute arbitrary host commands.

2026-05-05
CVE-2026-26332
Analyzed
9.8
patriksimek vm2

A vulnerability involving `SuppressedError` in the vm2 library allows attackers to escape the sandbox and execute arbitrary code on the host system.

2026-05-05
CVE-2026-24781
Analyzed
9.8
patriksimek vm2

A sandbox breakout vulnerability in the vm2 library's `inspect` function allows attackers to escape the sandbox and execute arbitrary commands on the...

2026-05-05
CVE-2026-24120
Analyzed
9.8
patriksimek vm2

An insufficient patch for a previous vm2 vulnerability allows attackers to bypass security measures and perform a sandbox breakout for arbitrary code...

2026-05-05
CVE-2026-24118
Analyzed
9.8
patriksimek vm2

A sandbox breakout vulnerability in the Node.js vm2 library allows attackers to escape the sandbox and execute arbitrary commands on the host system.

2026-05-05
CVE-2026-22709
Analyzed
9.8
patriksimek Multiple Products

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization...

2026-01-27