CVE-2026-47209
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
Summary
Remediation
Upgrade to the fixed version using your package manager.
npm install vm2@3.11.4
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| vm2 | npm | All versions | 3.11.4 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-693Protection Mechanism FailureMITRE
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 8.6 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-c4cf-2hgv-2qv6WEB
- https://nvd.nist.gov/vuln/detail/CVE-2026-47209ADVISORY
- https://github.com/patriksimek/vm2/commit/26d0318b5e6555be4b187ba05d6cf378ccecfe22WEB
- https://github.com/patriksimek/vm2PACKAGE
- https://github.com/patriksimek/vm2/releases/tag/v3.11.4WEB
Frequently Asked Questions
- What is CVE-2026-47209?
- vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.6/10).
- How do I check if my project is affected by CVE-2026-47209?
- CVE-2026-47209 affects vm2. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-47209 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
Also Known As
Related CVEs
- CVE-2026-45411CRITICAL
vm2 Has a Sandbox Breakout Using Async Generator
- CVE-2026-43997CRITICAL
vm2 Access to Host Object Enables Sandbox Escape
- CVE-2026-26332CRITICAL
VM2 Has a Sandbox Escape Issue via SuppressedError
- CVE-2026-47210CRITICAL
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CVE-2026-47208CRITICAL
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
- CVE-2026-44007CRITICAL
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
- CVE-2026-43999CRITICAL
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
- CVE-2026-44008CRITICAL
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies