PT-2026-45031 · Npm · Vm2

Published

2026-05-29

·

Updated

2026-05-30

·

CVE-2026-47208

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.4
Description A sandbox breakout exists that allows attackers to escape the VM2 sandbox and execute arbitrary commands on the host system. The issue occurs because the localPromise constructor calls this.then(undefined, eater) without calling resetPromiseSpecies. This omission allows a custom promise to supply a custom reject method to the executor, enabling the attacker to obtain a raw host error and break out of the sandbox.
Recommendations Update to version 3.11.4.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-47208
GHSA-76W7-J9CQ-RX2J

Affected Products

Vm2