{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-26956", "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "state": "PUBLISHED", "assignerShortName": "GitHub_M", "dateReserved": "2026-02-16T22:20:28.611Z", "datePublished": "2026-05-04T16:37:31.538Z", "dateUpdated": "2026-07-15T01:14:46.375Z" }, "containers": { "cna": { "title": "vm2: WASM Sandbox Escape (Node 25 only)", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-693", "lang": "en", "description": "CWE-693: Protection Mechanism Failure", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } } ], "references": [ { "name": "https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66", "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66" }, { "name": "https://github.com/patriksimek/vm2/releases/tag/v3.10.5", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/patriksimek/vm2/releases/tag/v3.10.5" } ], "affected": [ { "vendor": "patriksimek", "product": "vm2", "versions": [ { "version": "= 3.10.4", "status": "affected" } ] } ], "providerMetadata": { "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M", "dateUpdated": "2026-05-04T16:37:31.538Z" }, "descriptions": [ { "lang": "en", "value": "vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5." } ], "source": { "advisory": "GHSA-ffh4-j6h5-pg66", "discovery": "UNKNOWN" } }, "adp": [ { "references": [ { "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66", "tags": [ "exploit" ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-05T13:09:59.977323Z", "id": "CVE-2026-26956", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-05T13:10:04.497Z" } }, { "affected": [ { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:rhdh:1" ], "defaultStatus": "unaffected", "packageName": "rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor", "product": "Red Hat Developer Hub", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:rhdh:1" ], "defaultStatus": "unaffected", "packageName": "rhdh/rhdh-hub-rhel9", "product": "Red Hat Developer Hub", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/a:redhat:ansible_portal:2" ], "defaultStatus": "unaffected", "packageName": "ansible-automation-platform/automation-portal", "product": "Self-service automation portal 2", "vendor": "Red Hat" } ], "datePublic": "2026-05-04T16:37:31.538Z", "descriptions": [ { "lang": "en", "value": "A flaw was found in vm2, an open-source sandbox for Node.js. An attacker can exploit this vulnerability by running malicious code within the VM.run() function, allowing them to escape the sandbox and gain access to the host process. This can lead to arbitrary code execution on the host system, enabling the attacker to run host commands without any host cooperation." } ], "metrics": [ { "other": { "content": { "namespace": "https://access.redhat.com/security/updates/classification/", "value": "Important" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-653", "description": "Improper Isolation or Compartmentalization", "lang": "en", "type": "CWE" } ] } ], "references": [ { "tags": [ "vdb-entry", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/security/cve/CVE-2026-26956" }, { "name": "RHBZ#2466548", "tags": [ "issue-tracking", "x_refsource_REDHAT" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466548" }, { "tags": [ "x_sadp-csaf-vex" ], "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26956.json" } ], "timeline": [ { "lang": "en", "time": "2026-05-04T19:04:30.765Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2026-05-04T16:37:31.538Z", "value": "Made public." } ], "title": "vm2: Node.js: vm2: Arbitrary code execution via sandbox escape", "x_adpType": "supplier", "x_generator": { "engine": "sadp-cli 1.0.0" }, "providerMetadata": { "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c", "shortName": "redhat-SADP", "dateUpdated": "2026-07-15T01:14:46.375Z" } } ] } }