9.8
CVE-2026-44009
- EPSS 0.61%
- Veröffentlicht 13.05.2026 17:36:07
- Zuletzt bearbeitet 14.05.2026 15:17:22
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
vm2: Sandbox Breakout Through Null Proto Exception
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vm2 Project ≫ Vm2 SwPlatformnode.js Version < 3.11.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.447 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
https://github.com/patriksimek/vm2/security/advisories/GHSA-9vg3-4rfj-wgcm