PT-2026-45031 · Npm · Vm2

CVE-2026-47208

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.4
Description A sandbox breakout exists that allows attackers to escape the VM2 sandbox and execute arbitrary commands on the host system. The issue occurs because the localPromise constructor calls this.then(undefined, eater) without calling resetPromiseSpecies. This omission allows a custom promise to supply a custom reject method to the executor, enabling the attacker to obtain a raw host error and break out of the sandbox.
Recommendations Update to version 3.11.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47208
GHSA-76W7-J9CQ-RX2J

Affected Products

Vm2