PT-2026-38397 · Npm · Vm2

C0Rydoras

·

Published

2026-05-01

·

Updated

2026-06-15

·

CVE-2026-44006

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.0
Description A sandbox escape allows unauthenticated attackers to execute arbitrary system commands (RCE) on the host. The issue occurs because BaseHandler.getPrototypeOf can be reached via util.inspect, enabling the retrieval of arbitrary prototypes. By manipulating object prototypes through internal bridge functions, an attacker can gain access to the host's process object.
Recommendations Update to version 3.11.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06907
CVE-2026-44006
GHSA-QCP4-V2JJ-FJX8

Affected Products

Vm2