search
vm2
Trends
- 1Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594โ๐จ EUVD-2026-81594 ๐ Score: 2.3/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2: External
A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.
- 2Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ๐จ EUVD-2026-81591 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 NodeVM c
A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.
- 3Critical vm2 sandbox escape vulnerability flagged in Node.jsโ๐จ EUVD-2026-81593 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 sandbox e
A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.
- 4Critical 9.4-severity vulnerability disclosed in vm2 sandbox libraryโ๐จ EUVD-2026-81589 ๐ Score: 9.4/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 crypto bu
A high-severity vulnerability, EUVD-2026-81589, has been catalogued in vm2, the JavaScript sandbox library maintained by Patrik Simek. Scored 9.4 out of 10 under CVSS v3.1, the flaw involves vm2's crypto builtin loading attacker-supplied native code through the setEngine function, a path that could allow sandbox escapes or arbitrary code execution. The advisory was updated on October 1, 2026, and security teams are being urged to review any systems relying on vm2 for isolating untrusted JavaScript.