Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution


Certains articles de veille peuvent faire l'objet de traduction automatique.


Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution

A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system.
The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0 on the CVSS scoring system.
« In vm2 for version 3.10.0, Promise.prototype.then Promise.prototype.catch

Source : https://thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.html

Publications similaires

janvier 28, 2026
0 0 votes
Évaluation de l'article

Ce site utilise Akismet pour réduire les indésirables. Découvrez comment les données de vos commentaires sont traitées.

0 Commentaires
plus vieux
nouveaux plus votés