PT-2026-39191 · Npm · Vm2

·

CVE-2026-44008

·

Published

2026-05-08

·

Updated

2026-07-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VM2 (affected versions not specified)
Description A sandbox breakout allows attackers to execute arbitrary commands on the host system. The issue occurs because the neutralizeArraySpeciesBatch() function interacts with objects from an external context and can trigger a getter on the array prototype, exposing host objects into the sandbox. This mechanism enables an attacker to obtain the host Function object and achieve remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07027
CVE-2026-44008
ECHO-7225-874A-912C
GHSA-9QJ6-QJGG-37QQ

Affected Products

Vm2