Arbitrary Prototype Access in vm2 for Node.js
CVE-2026-44006
10CRITICAL
What is CVE-2026-44006?
The vm2 library, an open-source sandbox for Node.js, has a vulnerability that allows access to arbitrary prototypes through the BaseHandler.getPrototypeOf method. This issue poses a risk in versions prior to 3.11.0. The vulnerability has been addressed in version 3.11.0, mitigating the risk of unauthorized access to system prototypes.
Affected Version(s)
vm2 < 3.11.0
