Sandbox Escape Vulnerability in vm2 for Node.js
CVE-2026-43997
10CRITICAL
What is CVE-2026-43997?
The vm2 is an open-source virtual machine (VM)/sandbox environment for Node.js applications. A vulnerability has been identified in versions prior to 3.11.0 that allows attackers to potentially escape the sandbox by accessing the host Object. This can occur through various methods, such as leveraging HostObject.getOwnPropertySymbols to retrieve Symbol(nodejs.util.inspect.custom). The vulnerability has been addressed and mitigated in version 3.11.0.
Affected Version(s)
vm2 < 3.11.0
