MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #11

Critical vm2 sandbox escape vulnerability flagged in Node.js

Original: 🚨 EUVD-2026-81593 πŸ“Š Score: 9.3/10 (CVSS v3.1) πŸ“¦ Product: vm2 🏒 Vendor: patriksimek πŸ“… Updated: 2026-10-01 πŸ“ vm2 sandbox e

A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.

Why now: A 9.3-score sandbox escape in a widely used isolation library is highly relevant to developers running untrusted JavaScript.

vm2Patrik SimekNode.jsENISA

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/627926