CVE-2026-26956 is a critical sandbox escape vulnerability in the vm2 sandbox library for Node.js. The flaw affects vm2 version 3.10.4 and allows attacker-controlled code executed through VM.run() to break out of the intended isolation boundary and gain access to host-side objects, including the Node.js process object. Reported analyses indicate the escape is triggered by crafted JavaScript that causes a TypeError during Symbol-to-string coercion, and in affected environments this exception can be intercepted through WebAssembly exception handling in a way that bypasses vm2’s JavaScript-layer sanitization and proxy protections. By recovering an unsanitized host-realm error object and traversing its constructor chain, an attacker can reach host execution primitives and run arbitrary commands in the host process context. The issue is patched in vm2 version 3.10.5.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Another vm2 vulnerability mentioned only as part of the project's broader 2026 security history.
A vm2 sandbox escape CVE mentioned only as part of a historical list.
A critical vm2 WASM/JSTag escape to host RCE vulnerability mentioned as part of the 2026 vulnerability wave.
A prior critical vm2 sandbox escape vulnerability involving TypeError / Symbol-to-string conversion, cited in historical context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.