CVE-2026-24781
Last modified
CVE-2026-24781 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vm2 Project | Vm2 | < 3.11.0 |
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-v37h-5mfm-c47cExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-24781?
How severe is CVE-2026-24781?
How do I fix CVE-2026-24781?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-24775OpenProject is an open-source, web-based project management …7.3
- CVE-2026-24776OpenProject is an open-source, web-based project management …4.3
- CVE-2026-24777OpenProject is an open-source, web-based project management …6.7
- CVE-2026-24778Ghost is an open source content management system. In Ghost …6.1
- CVE-2026-24779vLLM is an inference and serving engine for large language m…7.1
- CVE-2026-24780AutoGPT is a platform that allows users to create, deploy, a…8.8
- CVE-2026-24782Kiteworks is a private data network (PDN). Prior to version …8.8
- CVE-2026-24783soroban-fixed-point-math is a fixed-point math library for S…7.5
- CVE-2026-24784DNN (formerly DotNetNuke) is an open-source web content mana…4.8
- CVE-2026-24785Clatter is a no_std compatible, pure Rust implementation of …9.1
- CVE-2026-24788RaspAP raspap-webgui versions prior to 3.3.6 contain an OS c…8.8
- CVE-2026-24789An unprotected API endpoint allows an attacker to remotely c…9.8
Are you affected by CVE-2026-24781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
