The maintainers of the Node.js sandbox library vm2 released v3.11.6 to patch five security advisories affecting earlier versions, including multiple sandbox escapes that can lead to remote code execution on the host and denial-of-service conditions through uncontrolled memory allocation. Reported flaws include CVE-2026-47698, which allows breakout via stacked Function.prototype.call indirection around dangerous host prototype mutators, and CVE-2026-47686, where unsanitized Error.cause values can leak powerful host objects such as process into sandboxed code. The release notes say the patch introduces no API changes for valid configurations while converting host errors into sandbox-realm errors to prevent host reference leakage.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The GHSA-m5w8-4gq2-6f8x advisory for vm2's os and dns wildcard exposure was reviewed and added to the GitHub Advisory Database. The issue had been reported by offset via GitHub Security Advisory.
Security-advisories@github.com received submissions for CVE-2026-47683, CVE-2026-47698, and CVE-2026-47686, covering bufferAllocLimit bypass, stacked Function.prototype indirection sandbox escape, and Error.cause sanitization bypass issues in vm2.
vm2 version 3.11.6 was released as a patch update that closed five security advisories, including sandbox escape, host-state exposure, and memory-exhaustion denial-of-service issues. The release also changed NodeVM wildcard behavior to deny os and dns access and hardened error sanitization.
A fix for GHSA-m5w8-4gq2-6f8x was committed to vm2's main branch, adding os and dns to the dangerous built-ins denylist and blocking related module names under wildcard builtin access.
OX Security published research describing how vm2 NodeVM configurations using builtin:['*'] could expose host os and dns modules, enabling host information disclosure and persistent DNS resolver manipulation until patched in 3.11.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
ox.security
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.