CRITICAL 9.9 GitHub

CVE-2026-47686

VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE

**Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) **CWE:** CWE-693 (Protection Mechanism Failure) **Prerequisite:** Embedder exposes a host function that throws an Error with `.cause` referencing a powerful host object (e.g., `process`) ## Summary I found that `handleException()` in `lib/setup-sandbox.js` recursively sanitizes sub-errors for `SuppressedError` and `AggregateError`, but completely ignores the ES2022 `Error.cause` property. When san

Affected Products

References

Published: 2026-08-17 · Source: GitHub · Feed updated: 2026-08-17
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-08-17 via GitHub. Affected: npm/vm2 <= 3.11.5.

Risk Timeline

CVE Disclosed2026-08-17 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-47698vm2: Sandbox Breakout Using Dangerous Host Proto MutatorsCRITICAL9.8
CVE-2026-55157Token Optimizer MCP: OS command injection in smart_user via username in get-userHIGH8.4
CVE-2026-53728Medplum: Improper Validation of Redirect URI in External Auth Callback allows AuHIGH7.1
CVE-2026-55090Etherpad has stored XSS in HTML export via unescaped attribute-pool valuesHIGH
CVE-2026-47683vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLikeHIGH
CVE-2026-40345DeepmergeTS has stack exhaustion when merging recursive object graphsHIGH
vulnfeed aggregates 11030 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.