PT-2026-39191 · Npm · Vm2

Xmiliah

·

Published

2026-05-08

·

Updated

2026-05-13

·

CVE-2026-44008

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VM2 (affected versions not specified)
Description A sandbox breakout allows attackers to execute arbitrary commands on the host system. The issue occurs because the neutralizeArraySpeciesBatch() function interacts with objects from an external context and can trigger a getter on the array prototype, exposing host objects into the sandbox. This mechanism enables an attacker to obtain the host Function object and achieve remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2026-07027
CVE-2026-44008
GHSA-9QJ6-QJGG-37QQ

Affected Products

Vm2