Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #11
Critical vm2 sandbox escape vulnerability flagged in Node.js
Original: π¨ EUVD-2026-81593 π Score: 9.3/10 (CVSS v3.1) π¦ Product: vm2 π’ Vendor: patriksimek π Updated: 2026-10-01 π vm2 sandbox e
A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.
Why now: A 9.3-score sandbox escape in a widely used isolation library is highly relevant to developers running untrusted JavaScript.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/627926