A critical sandbox-escape flaw in the Node.js library vm2 allows attackers to bypass protections around Promise.prototype.then and Promise.prototype.catch, break out of the sandbox, and execute arbitrary code on the host. The vulnerability, tracked as CVE-2026-22709 with a CVSS 9.8 score, affects vm2 3.10.0 and earlier and strikes at the library’s core purpose of safely running untrusted JavaScript. Users were urged to upgrade immediately to vm2 3.10.2 or later.
The disclosure follows broader concerns about vm2’s long-term viability after repeated sandbox escapes and a prior GitHub advisory describing additional flaws that could lead to remote code execution. Semgrep reported that the project was later discontinued after maintainers concluded vm2’s dependence on Node’s vm module and JavaScript proxy behavior made the sandboxing model fundamentally difficult to secure. The maintainer recommended isolated-vm as an alternative, while warning signs around maintenance and ecosystem support continue to raise risk for organizations that rely on JavaScript sandboxing libraries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A critical sandbox escape vulnerability, CVE-2026-22709, was fixed in the vm2 library for Node.js. The flaw affected vm2 3.10.0 and earlier and allowed bypass of Promise.prototype.then and Promise.prototype.catch sanitization to escape the sandbox and execute arbitrary code.
Following the July 12 advisory, maintainer Patrick Simek shut down the vm2 project, said no fix was planned, and recommended isolated-vm as a replacement. The decision was attributed to underlying design limitations that made sandbox escapes effectively unfixable.
A GitHub security advisory published on July 12 disclosed two vm2 sandbox escape vulnerabilities that could lead to remote code execution. The disclosure marked a major escalation in the project's 2023 security issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesemgrep.dev
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.